Skip to main content

US DOT issues federal guidance for improving motor vehicle cyber security

The US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security. The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised ident
October 25, 2016 Read time: 2 mins
The 324 US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security.

The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised identification and protection of critical vehicle controls and consumers' personal data. Further, it recommends that companies should consider the full life-cycle of their vehicles and facilitate rapid response and recovery from cyber security incidents.

This guidance also highlights the importance of making cyber security a top leadership priority for the automotive industry, and suggests that companies should demonstrate it by allocating appropriate and dedicated resources, and enabling seamless and direct communication channels though organisational ranks related to vehicle cyber security matters.

"Cyber security is a safety issue, and a top priority at the Department," said US Transportation Secretary Anthony Foxx. "Our intention with today's guidance is to provide best practices to help protect against breaches and other security failures that can put motor vehicle safety."

"In the constantly changing environment of technology and cyber security, no single or static approach is sufficient," said NHTSA Administrator Dr Mark Rosekind. "Everyone involved must keep moving, adapting, and improving to stay ahead of the bad guys."

In addition to product development, the guidance suggests best practices for researching, investigating, testing and validating cyber security measures, NHTSA recommends the industry self-audit and consider vulnerabilities and exploits that may impact their entire supply-chain of operations. The safety agency also recommends employee training to educate the entire automotive workforce on new cyber security practices and to share lessons learned with others.

For more information on companies in this article

Related Content

  • Foreign drivers cannot avoid paying Dart Charge, says RHA
    August 22, 2017
    The news that over one million non-UK drivers have managed to avoid paying the Dart Charge when travelling over the Dartford Crossing comes as little surprise to the Road Haulage Association *RHA). Speaking to BBC Kent, RHA policy director Duncan Buchanan said: “This issue was identified from the moment the Freeflow system was introduced, and it is still a problem. Foreign drivers should pay: it’s as simple as that. It is very concerning that there are still hauliers making the crossing for free.” Fin
  • Does ADAS create as many problems as it solves
    September 23, 2014
    Victoria Banks and Neville Stanton [1] of Southampton University’s Transportation Research Group examine the real impact of creeping driver automation. Safety research suggests that 90% of accidents are thought to be a result of driver inattentiveness to unpredictable or incomplete information and the vision is that highly automated vehicles will lead to accident-free driving in the future.
  • Wi-SUN: here’s why mesh networking works
    May 10, 2019
    There are several networking options available for smart city planners. Phil Beecher of Wi-SUN Alliance makes the case for wireless mesh networks when it comes to rolling out IoT solutions The Internet of Things (IoT) is growing fast. Connecting thousands of sensors and control systems in bi-directional networks is paving the way for a new generation of smart city and transport infrastructures. For many of these applications, wireless connectivity is essential where cable installation is not practical.
  • Joint venture delivers integrated parking payment
    October 31, 2014
    Mobile payment solutions provider Parkmobile USA is to partner with SP Plus Corporation (SP+) in a joint venture that will combine two parking transaction engines to deliver on-demand and prepaid transaction processing for on- and off-street parking and transportation services. Parkmobile will contribute its on-demand parking transaction engine that allows consumers to transact real-time payment for parking privileges in both on- and off-street environments. SP+ will contribute its proprietary Click and