Skip to main content

US DOT issues federal guidance for improving motor vehicle cyber security

The US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security. The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised ident
October 25, 2016 Read time: 2 mins
The 324 US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security.

The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised identification and protection of critical vehicle controls and consumers' personal data. Further, it recommends that companies should consider the full life-cycle of their vehicles and facilitate rapid response and recovery from cyber security incidents.

This guidance also highlights the importance of making cyber security a top leadership priority for the automotive industry, and suggests that companies should demonstrate it by allocating appropriate and dedicated resources, and enabling seamless and direct communication channels though organisational ranks related to vehicle cyber security matters.

"Cyber security is a safety issue, and a top priority at the Department," said US Transportation Secretary Anthony Foxx. "Our intention with today's guidance is to provide best practices to help protect against breaches and other security failures that can put motor vehicle safety."

"In the constantly changing environment of technology and cyber security, no single or static approach is sufficient," said NHTSA Administrator Dr Mark Rosekind. "Everyone involved must keep moving, adapting, and improving to stay ahead of the bad guys."

In addition to product development, the guidance suggests best practices for researching, investigating, testing and validating cyber security measures, NHTSA recommends the industry self-audit and consider vulnerabilities and exploits that may impact their entire supply-chain of operations. The safety agency also recommends employee training to educate the entire automotive workforce on new cyber security practices and to share lessons learned with others.

For more information on companies in this article

Related Content

  • Copenhagen to showcase ITS in action at ITSWC 2018
    December 18, 2017
    As delegates head for the 2017 ITS World Congress in Montreal, we talk to Copenhagen mayor Morten Kabell about why his city is the ideal location for next year’s event. It may have been a long time coming but the ITS World Congress will be in Copenhagen in 2018 and there can be few more fitting places to host the event. By any number of metrics - interconnected transport, cycle commuting, safer streets, reduced pollution, sustainable energy and quality of life - the Danish capital has implemented what m
  • New solutions for catching texting drivers
    October 28, 2016
    Many countries have laws prohibiting texting while driving but enforcement is proving difficult – David Crawford looks at some new approaches being tried by authorities. Finding definitive solutions – technological, regulatory and educational - to the potentially lethal practice of people driving while using mobile phones is proving elusive, while the stakes grow higher.
  • Mercedes to test autonomous vehicles at secure US Navy base
    October 3, 2014
    Mercedes-Benz is to begin testing its autonomous cars on a unique site in California, at the Contra Costa Transportation Authority Concord Naval Weapons Station (CNWS), the largest test bed site in the US. Since mid-September the company has also held an official licence, issued by California, to test self-driving vehicles on public roads. The additional testing opportunities provided by the CNWS site will enable the company to significantly expand the scope of its research activities. With a test ar
  • Motown morphs into Mobility City
    August 7, 2018
    Detroit was once a byword for urban decay – but ITS America recently held its annual meeting there. This gave David Arminas a chance to assess how fast Motor City is moving down the road to recovery. Motor City, as Detroit is still called, was on its financial knees only five short years ago. The future looked bleak as the city and greater urban area bled jobs and population. It was on 18 July 2013 that Motown, as Detroit is also known, filed for Chapter 9 bankruptcy protection, the