Skip to main content

US DOT issues federal guidance for improving motor vehicle cyber security

The US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security. The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised ident
October 25, 2016 Read time: 2 mins
The 324 US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security.

The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised identification and protection of critical vehicle controls and consumers' personal data. Further, it recommends that companies should consider the full life-cycle of their vehicles and facilitate rapid response and recovery from cyber security incidents.

This guidance also highlights the importance of making cyber security a top leadership priority for the automotive industry, and suggests that companies should demonstrate it by allocating appropriate and dedicated resources, and enabling seamless and direct communication channels though organisational ranks related to vehicle cyber security matters.

"Cyber security is a safety issue, and a top priority at the Department," said US Transportation Secretary Anthony Foxx. "Our intention with today's guidance is to provide best practices to help protect against breaches and other security failures that can put motor vehicle safety."

"In the constantly changing environment of technology and cyber security, no single or static approach is sufficient," said NHTSA Administrator Dr Mark Rosekind. "Everyone involved must keep moving, adapting, and improving to stay ahead of the bad guys."

In addition to product development, the guidance suggests best practices for researching, investigating, testing and validating cyber security measures, NHTSA recommends the industry self-audit and consider vulnerabilities and exploits that may impact their entire supply-chain of operations. The safety agency also recommends employee training to educate the entire automotive workforce on new cyber security practices and to share lessons learned with others.

For more information on companies in this article

Related Content

  • Byton debuts smart intuitive vehicle at CES 2018
    January 8, 2018
    Byton’s new smart intuitive vehicle, which features an all-new design and innovative human-vehicle interaction, has made its global debut at the Consumer Electronics Show 2018. It is designed with the intention of providing a shared, smart mobility and autonomous driving solution and will be available in China next year and in the U.S. and Europe in 2020. The car is equipped with multiple display screens, with a traditional console replaced by a Shared Experience Display that enables content to be shared
  • Connecticut Transit uses web feedback to improve user experience
    May 27, 2014
    Connecticut champions open government and open data to help fostertransparency, accountability and citizen engagement – and that includes transportation matters as Andrew Bardin Williams discovers. The last thing anyone wanted was to inconvenience or displace others - least of all people who lived and worked in the neighbourhood. Yet, workers in an office building in downtown New Haven, Conn., were tired of shuffling through hoards of people who kept sitting on the stoop to the building while waiting for th
  • Eco fuel economy
    April 19, 2012
    A study conducted by VTT Technical Research Centre of Finland suggests that there is practically no difference between commercial petrol grades 95E10 and 98E5 sold in Finland with regard to fuel consumption during normal driving. The finding is based on driving tests conducted by VTT using six used cars of different make under laboratory conditions. It has been claimed in public that fuel consumption is higher with 95E10 petrol than with its predecessor 95E or the 98E5 petrol currently on the market. The su
  • Co-operative enforcement equals greater road safety
    January 23, 2012
    Do cooperative infrastructures offer a ready solution for automated enforcement? If we accept that enforcement is all about safety and not revenue generation, then it is perhaps time to start looking at just what cooperative infrastructures will have to offer. Identification, verification, preserving the evidence chain... all the current headaches of effective automated enforcement could perceivably be solved by the technologies and protocols encompassed by two-way communications between infrastructure and