Skip to main content

US DOT issues federal guidance for improving motor vehicle cyber security

The US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security. The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised ident
October 25, 2016 Read time: 2 mins
The 324 US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security.

The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised identification and protection of critical vehicle controls and consumers' personal data. Further, it recommends that companies should consider the full life-cycle of their vehicles and facilitate rapid response and recovery from cyber security incidents.

This guidance also highlights the importance of making cyber security a top leadership priority for the automotive industry, and suggests that companies should demonstrate it by allocating appropriate and dedicated resources, and enabling seamless and direct communication channels though organisational ranks related to vehicle cyber security matters.

"Cyber security is a safety issue, and a top priority at the Department," said US Transportation Secretary Anthony Foxx. "Our intention with today's guidance is to provide best practices to help protect against breaches and other security failures that can put motor vehicle safety."

"In the constantly changing environment of technology and cyber security, no single or static approach is sufficient," said NHTSA Administrator Dr Mark Rosekind. "Everyone involved must keep moving, adapting, and improving to stay ahead of the bad guys."

In addition to product development, the guidance suggests best practices for researching, investigating, testing and validating cyber security measures, NHTSA recommends the industry self-audit and consider vulnerabilities and exploits that may impact their entire supply-chain of operations. The safety agency also recommends employee training to educate the entire automotive workforce on new cyber security practices and to share lessons learned with others.

For more information on companies in this article

Related Content

  • Travel restrictions cause ITS professionals' knowledge gap
    February 2, 2012
    Andrew Barriball once again campaigns for senior USDOT officials to see sense and lift some of the restrictions on out-of-state travel for transportation professionals. The ability to attend conferences and exhibitions is not a luxury, he says; it is a valid and cost-effective way of advancing the state of the traffic management art
  • South Africa's traffic management and enforcement gears up
    February 1, 2012
    Paul Vorster, CEO of ITS South Africa, takes a look at the national enforcement situation in the year when the country gears up to host the FIFA Soccer World Cup. There are four main drivers pushing the growth of ITS-related law enforcement within South Africa. These are: transport operations associated with hosting the FIFA Soccer World Cup 2010; traffic management linked to increasing congestion; the development of new public transport systems such as BRT; and vehicle and driver-related crime.
  • EU steps up efforts to tackle cyber threats
    July 7, 2016
    The Commission has launched a new public-private partnership with the non-profit European Cyber Security Organisation (ECSO) on cyber-security that is expected to trigger US$2 billion (€1.8 billion) of investment by 2020. This is part of a series of new initiatives to better equip Europe against cyber-attacks and to strengthen the competitiveness of its cyber-security sector. The EU plans to invest US$500 million (€450 million) under its research and innovation (R&I) programme Horizon 2020, with the rema
  • Improve and increase mass transit systems to minimise congestion
    January 24, 2012
    Rather looking to solve congestion by spreading the load, perhaps we need to look at concentrating it. Michael L. Sena writes. We humans were made to walk and run at embarrassingly slow speeds by comparison with other, more fleet-footed organisms. The sea is not our natural habitat and we were definitely not designed to fly unaided. Nevertheless, humankind has evolved a method of living during the past century that is dependent on transporting its members over very long distances during relatively short per