A TARA that re-computes
when the system changes.
Threat scenarios, damage scenarios, attack paths and risk values live on the same graph as the architecture. Change an interface — affected lines re-flag. Land a control — feasibility recalculates. No frozen spreadsheet drifting from reality.
STRIDE per asset.
Proposed, not typed.
AI proposes threat and damage scenarios per component, with rationale. Engineers accept, edit or reject — nothing enters the assessment unreviewed.
Aggregated trees,
not tribal knowledge.
Attack paths aggregate across components into one tree per asset. Each step carries its feasibility rating — mitigate a step and every path through it re-scores.
Impact × feasibility.
Computed, defensible.
Risk values derive from rated impact and attack feasibility per §15 — every cell in the heat map traces back to the scenarios behind it.
Every decision keeps
its chain.
Treatment decisions spawn goals and requirements on the same graph — continue on Sheet 03 · Assurance to see them proven.