Skip to main content

US DOT issues federal guidance for improving motor vehicle cyber security

The US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security. The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised ident
October 25, 2016 Read time: 2 mins
The 324 US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security.

The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised identification and protection of critical vehicle controls and consumers' personal data. Further, it recommends that companies should consider the full life-cycle of their vehicles and facilitate rapid response and recovery from cyber security incidents.

This guidance also highlights the importance of making cyber security a top leadership priority for the automotive industry, and suggests that companies should demonstrate it by allocating appropriate and dedicated resources, and enabling seamless and direct communication channels though organisational ranks related to vehicle cyber security matters.

"Cyber security is a safety issue, and a top priority at the Department," said US Transportation Secretary Anthony Foxx. "Our intention with today's guidance is to provide best practices to help protect against breaches and other security failures that can put motor vehicle safety."

"In the constantly changing environment of technology and cyber security, no single or static approach is sufficient," said NHTSA Administrator Dr Mark Rosekind. "Everyone involved must keep moving, adapting, and improving to stay ahead of the bad guys."

In addition to product development, the guidance suggests best practices for researching, investigating, testing and validating cyber security measures, NHTSA recommends the industry self-audit and consider vulnerabilities and exploits that may impact their entire supply-chain of operations. The safety agency also recommends employee training to educate the entire automotive workforce on new cyber security practices and to share lessons learned with others.

For more information on companies in this article

Related Content

  • Here to acquire ATS to power software updates for connected and AVs
    November 30, 2017
    Here Technologies (HT) has announced plans to acquire German-based ATS Telematics Systems (ATS) which develops over-the-air (OTA) software updating technology for the automotive industry. The transaction aims to leverage the full potential of connected and autonomous vehicles that draw on HD maps to provide a near real-time picture road environments.
  • Increase in Scotland’s road deaths ‘deeply troubling’, says Brake
    June 15, 2017
    Transport Scotland has released provisional headline figures for road casualties reported to the police in Scotland in 2016, showing 191 people were killed in reported accidents in 2016 - 23 more than in 2015.
  • New opportunities in a data-rich future
    March 19, 2014
    Jason Barnes looks at where the detection and monitoring sector is heading. In the future, there will be no such thing as an un-instrumented road. Just a short time ago, that could have been a quote from a high-level policy document but with the first arrivals of vehicles with 802.11p connectivity – the door-opener to Vehicle-to-X (V2X) applications – it’s a statement which has increasing validity. The technology which uses our roads will also provide information on road conditions but V2X isn’t the only
  • Michigan researchers show how easy it is to hack trucks
    August 5, 2016
    Cybersecurity researchers have already shown how easy it is to hack a Jeep Cherokee and take control of its brakes and steering, resulting in a recall for the vulnerability to be corrected. At the Usenix Workshop on Offensive Technologies conference next week, a group of University of Michigan researchers plan to demonstrate how trucks, which have also begun adding similar electronic control system, can be vulnerable to hacking. They plan to show how the openness of the SAE J1939 standard used across