Skip to main content

US DOT issues federal guidance for improving motor vehicle cyber security

The US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security. The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised ident
October 25, 2016 Read time: 2 mins
The 324 US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security.

The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised identification and protection of critical vehicle controls and consumers' personal data. Further, it recommends that companies should consider the full life-cycle of their vehicles and facilitate rapid response and recovery from cyber security incidents.

This guidance also highlights the importance of making cyber security a top leadership priority for the automotive industry, and suggests that companies should demonstrate it by allocating appropriate and dedicated resources, and enabling seamless and direct communication channels though organisational ranks related to vehicle cyber security matters.

"Cyber security is a safety issue, and a top priority at the Department," said US Transportation Secretary Anthony Foxx. "Our intention with today's guidance is to provide best practices to help protect against breaches and other security failures that can put motor vehicle safety."

"In the constantly changing environment of technology and cyber security, no single or static approach is sufficient," said NHTSA Administrator Dr Mark Rosekind. "Everyone involved must keep moving, adapting, and improving to stay ahead of the bad guys."

In addition to product development, the guidance suggests best practices for researching, investigating, testing and validating cyber security measures, NHTSA recommends the industry self-audit and consider vulnerabilities and exploits that may impact their entire supply-chain of operations. The safety agency also recommends employee training to educate the entire automotive workforce on new cyber security practices and to share lessons learned with others.

For more information on companies in this article

Related Content

  • Mexico and the US slow to adopt ETC interoperability
    April 12, 2013
    Splinteroperability is a word devised by Travis P. Dunn and Victor J. Michelet C. to encapsulate the lack of progress towards ETC harmonisation in the US and Mexico. Five thousand miles of tolled roads and bridges. Widespread implementation of electronic toll collection (ETC) systems. One dominant interoperable ETC service provider covering just over half the nation’s toll facilities. Numerous other ETC service providers offering alternative visions of interoperability. Years of customer requests for better
  • Germany shifts gear on two-wheel traffic
    July 16, 2020
    National Cycling Plan 3.0 carries on from previous strategies
  • ASECAP examines tolling during downturns
    September 22, 2014
    ASECAP debated the impact of the financial crises on Europe’s tolling companies and considered the future in diverse economies. Colin Sowman picks some of the highlights. This year ASECAP (Association Europeenne des Concessionnaires d’Autoroutes et d’Ouvrages a’ Peage, with members in 21 countries managing 46,000km of roadway) held its annual Study & Information Days in Athens, Greece – one of the country hardest hit by recent economic problems. While the theme of the conference, Ensuring Sustainability in
  • Navigating the data privacy landscape
    July 24, 2023
    If customer data is not protected then the journey towards better, less polluting public transport solutions is likely to be delayed, warns Alexis Suggett of Cubic Transportation Systems