Skip to main content

US DOT issues federal guidance for improving motor vehicle cyber security

The US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security. The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised ident
October 25, 2016 Read time: 2 mins
The 324 US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security.

The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised identification and protection of critical vehicle controls and consumers' personal data. Further, it recommends that companies should consider the full life-cycle of their vehicles and facilitate rapid response and recovery from cyber security incidents.

This guidance also highlights the importance of making cyber security a top leadership priority for the automotive industry, and suggests that companies should demonstrate it by allocating appropriate and dedicated resources, and enabling seamless and direct communication channels though organisational ranks related to vehicle cyber security matters.

"Cyber security is a safety issue, and a top priority at the Department," said US Transportation Secretary Anthony Foxx. "Our intention with today's guidance is to provide best practices to help protect against breaches and other security failures that can put motor vehicle safety."

"In the constantly changing environment of technology and cyber security, no single or static approach is sufficient," said NHTSA Administrator Dr Mark Rosekind. "Everyone involved must keep moving, adapting, and improving to stay ahead of the bad guys."

In addition to product development, the guidance suggests best practices for researching, investigating, testing and validating cyber security measures, NHTSA recommends the industry self-audit and consider vulnerabilities and exploits that may impact their entire supply-chain of operations. The safety agency also recommends employee training to educate the entire automotive workforce on new cyber security practices and to share lessons learned with others.

For more information on companies in this article

Related Content

  • State DOTs discuss ITS lessons learned at ITSA 2016 San Jose
    May 27, 2016
    Department of Transportation (DOT) executives in charge of intelligent transportation deployment decisions will participate in a DOT Roundtable on Sunday, June 12, 3:00-4:45 pm, at McEnery Convention Center as part of ITS America 2016 San Jose. These leaders, from across the United States, will discuss their states’ experiences, successes, failures, challenges, and lessons learned in launching ITS projects while, on broader scale, endeavouring to prepare their state’s infrastructure to meet and support tomo
  • Autonomous vehicle accuracy mapping from TomTom
    October 8, 2015
    Pride of place on satellite navigation pioneer TomTom’s stand is very high resolution 3D mapping, initially for Germany, which it says provides the 10cm accuracy necessary for highly automated vehicles. Its mainstream mapping is also high definition meaning the image can be used on any size of screen – as visitors can see.
  • European ideal poses local problems for toll companies
    December 16, 2013
    Being the first organisation attempting to implement an interoperable system poses challenges and increases risk that must be managed to realise the benefits. The European Electronic Toll Service (EETS) legislation aims to avoid the problems experienced in the USA and provide road users with seamless travel across the EU but it can pose big problems for some toll operators. Take, for instance, the case of the Humber Bridge in the UK. Its case was highlighted at the recent ITS World Congress by Tim Gammons,
  • Over-height vehicle solution proves its worth on smart motorway
    November 17, 2014
    Temporary intelligent transport system (ITS) solutions provider, Mobile Visual Information Systems Ltd (MVIS), has supplied the BAM Morgan Sindall joint venture with a temporary over-height detection solution for use on the M62 and M1 junction 39 to 42 smart motorway project. Developed by MVIS and its partner, Intellicone temporary work zone safety system creator, Highway Resource Solutions (HRS), the over-height detection solution is part of the partners’ work-zone safety portfolio, the first temporary