Skip to main content

US DOT issues federal guidance for improving motor vehicle cyber security

The US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security. The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised ident
October 25, 2016 Read time: 2 mins
The 324 US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security.

The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised identification and protection of critical vehicle controls and consumers' personal data. Further, it recommends that companies should consider the full life-cycle of their vehicles and facilitate rapid response and recovery from cyber security incidents.

This guidance also highlights the importance of making cyber security a top leadership priority for the automotive industry, and suggests that companies should demonstrate it by allocating appropriate and dedicated resources, and enabling seamless and direct communication channels though organisational ranks related to vehicle cyber security matters.

"Cyber security is a safety issue, and a top priority at the Department," said US Transportation Secretary Anthony Foxx. "Our intention with today's guidance is to provide best practices to help protect against breaches and other security failures that can put motor vehicle safety."

"In the constantly changing environment of technology and cyber security, no single or static approach is sufficient," said NHTSA Administrator Dr Mark Rosekind. "Everyone involved must keep moving, adapting, and improving to stay ahead of the bad guys."

In addition to product development, the guidance suggests best practices for researching, investigating, testing and validating cyber security measures, NHTSA recommends the industry self-audit and consider vulnerabilities and exploits that may impact their entire supply-chain of operations. The safety agency also recommends employee training to educate the entire automotive workforce on new cyber security practices and to share lessons learned with others.

For more information on companies in this article

Related Content

  • Consortium welcomes Euro ITS directive 
    February 2, 2022
    C2C-CC supports proposed focus on interoperability and backward compatibility
  • Report urges US$25 billion transport improvement plan
    August 6, 2014
    The One North report, produced by the city regions of Leeds, Liverpool, Manchester, Newcastle and Sheffield in the UK, puts forward a strategic proposition for transport in the north of the country. The US$16.8-US$25.2 billion plan urges major changes in connectivity and capacity between the northern cities over the next 15 years and proposes optimisation of strategic highway capacity, a new high speed trans-Pennine rail route and improved city region rail networks interconnected with HS2 services, new inte
  • An honest relationship
    July 19, 2012
    Consider this: "the most important reform should be that of speed limits and the criteria by which they are set". And this: "a successful road safety solution reduces casualties and catches few people because offence rates are so low". Both statements come from the article on pages 28-30 of this issue on business models for automated enforcement. Both come from established figures in the field (respectively, Paolo Sodi of Sodi Scientifica and Geoff Collins of Speed Check Services); and both highlight the ya
  • Digital identities in Europe could top €1tn by 2020 says BCS
    October 29, 2013
    The economic value of our digital identities is growing fast and could reach 1 trillion euros in Europe by 2020, according to estimates from the Boston Consulting Group. Digital identities boost economic efficiency, help focus research and marketing efforts while spurring the creation of personalized products and services that, in turn, drive revenues. For consumers, the benefits are compelling as products and services are tailored to their needs and requirements, says the report.