Skip to main content

US DOT issues federal guidance for improving motor vehicle cyber security

The US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security. The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised ident
October 25, 2016 Read time: 2 mins
The 324 US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security.

The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised identification and protection of critical vehicle controls and consumers' personal data. Further, it recommends that companies should consider the full life-cycle of their vehicles and facilitate rapid response and recovery from cyber security incidents.

This guidance also highlights the importance of making cyber security a top leadership priority for the automotive industry, and suggests that companies should demonstrate it by allocating appropriate and dedicated resources, and enabling seamless and direct communication channels though organisational ranks related to vehicle cyber security matters.

"Cyber security is a safety issue, and a top priority at the Department," said US Transportation Secretary Anthony Foxx. "Our intention with today's guidance is to provide best practices to help protect against breaches and other security failures that can put motor vehicle safety."

"In the constantly changing environment of technology and cyber security, no single or static approach is sufficient," said NHTSA Administrator Dr Mark Rosekind. "Everyone involved must keep moving, adapting, and improving to stay ahead of the bad guys."

In addition to product development, the guidance suggests best practices for researching, investigating, testing and validating cyber security measures, NHTSA recommends the industry self-audit and consider vulnerabilities and exploits that may impact their entire supply-chain of operations. The safety agency also recommends employee training to educate the entire automotive workforce on new cyber security practices and to share lessons learned with others.

For more information on companies in this article

Related Content

  • Arilou develops central management hub for automotive ethernet
    March 5, 2018
    Arilou Information Security Technologies (Arilou) has released central management technology with the intention of enabling dynamic and secure control of in-vehicle communication networks for connected and autonomous vehicles equipped with Ethernet networks. The supplier of cyber security solutions aims to set a standard for Ethernet integration as well as provide security for connected cars of the future. Called the Ethernet Security Hub, the tool aims to allow complete, real-time management of the
  • Five micromobility operators + 10 recommendations = regulated cities
    March 27, 2023
    At least, that's what Dott, Lime, Superpedestrian, Tier and Voi think in new guidance
  • Public Private Partnerships to gather pace in the US
    April 29, 2015
    Public Private Partnerships are set to play a big role in transportation funding as Andrew Bardin Williams discovers. The old joke goes that the road from New York to Chicago is paved with potholes. For decades, drivers from New York and New Jersey traveling across Pennsylvania to visit the Midwest have lambasted the Commonwealth’s roadways for their lack of smooth pavement.
  • What does 2023 have in store for ITS?
    December 30, 2022
    From VRUs to EVs, from customer experience to connected vehicles, here are some thoughts...