Skip to main content

US DOT issues federal guidance for improving motor vehicle cyber security

The US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security. The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised ident
October 25, 2016 Read time: 2 mins
The 324 US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security.

The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised identification and protection of critical vehicle controls and consumers' personal data. Further, it recommends that companies should consider the full life-cycle of their vehicles and facilitate rapid response and recovery from cyber security incidents.

This guidance also highlights the importance of making cyber security a top leadership priority for the automotive industry, and suggests that companies should demonstrate it by allocating appropriate and dedicated resources, and enabling seamless and direct communication channels though organisational ranks related to vehicle cyber security matters.

"Cyber security is a safety issue, and a top priority at the Department," said US Transportation Secretary Anthony Foxx. "Our intention with today's guidance is to provide best practices to help protect against breaches and other security failures that can put motor vehicle safety."

"In the constantly changing environment of technology and cyber security, no single or static approach is sufficient," said NHTSA Administrator Dr Mark Rosekind. "Everyone involved must keep moving, adapting, and improving to stay ahead of the bad guys."

In addition to product development, the guidance suggests best practices for researching, investigating, testing and validating cyber security measures, NHTSA recommends the industry self-audit and consider vulnerabilities and exploits that may impact their entire supply-chain of operations. The safety agency also recommends employee training to educate the entire automotive workforce on new cyber security practices and to share lessons learned with others.

For more information on companies in this article

Related Content

  • 'Tipping point' for shared mobility
    November 16, 2022
    New initiative comes as Cop27 sees only 'minor role' for the sector in decarbonising transport
  • New US fuel efficiency standards would cost over US$65 billion in lost revenue
    April 17, 2012
    Friday’s proposal by the Obama Administration to increase fuel efficiency standards for cars and light trucks to an average 54.5 miles per gallon (4.32 litres/100 km) between 2017 and 2025 would result in the loss of more than $65 billion in federal funding for state and local highway, bridge and transit improvements, an analysis by the American Road & Transportation Builders Association (ARTBA) shows.
  • Gridsmart creates cybersecurity division
    May 11, 2018
    Gridsmart Technologies has formed a cyber security group to help transportation industry technology and infrastructure partners build security programmes for their organisations. The Gridsmart Information Security and Threat Intelligence Division (ISTI) will provide vulnerability and threat assessments and tailored security strategies to private companies, state and municipal Departments of Transportations and other groups working to enhance their technical infrastructure. ISTI, led by cyber security
  • Dr Hiroyuki Watanabe looks ahead to 20th World Congress in Tokyo
    October 24, 2012
    The 20th ITS World Congress will be held in Tokyo from 14-18 October, 2013. Dr Hiroyuki Watanabe, Chairman, Japan Organising Committee reveals some of the highlights that delegates can look forward to.