Skip to main content

US DOT issues federal guidance for improving motor vehicle cyber security

The US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security. The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised ident
October 25, 2016 Read time: 2 mins
The 324 US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security.

The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised identification and protection of critical vehicle controls and consumers' personal data. Further, it recommends that companies should consider the full life-cycle of their vehicles and facilitate rapid response and recovery from cyber security incidents.

This guidance also highlights the importance of making cyber security a top leadership priority for the automotive industry, and suggests that companies should demonstrate it by allocating appropriate and dedicated resources, and enabling seamless and direct communication channels though organisational ranks related to vehicle cyber security matters.

"Cyber security is a safety issue, and a top priority at the Department," said US Transportation Secretary Anthony Foxx. "Our intention with today's guidance is to provide best practices to help protect against breaches and other security failures that can put motor vehicle safety."

"In the constantly changing environment of technology and cyber security, no single or static approach is sufficient," said NHTSA Administrator Dr Mark Rosekind. "Everyone involved must keep moving, adapting, and improving to stay ahead of the bad guys."

In addition to product development, the guidance suggests best practices for researching, investigating, testing and validating cyber security measures, NHTSA recommends the industry self-audit and consider vulnerabilities and exploits that may impact their entire supply-chain of operations. The safety agency also recommends employee training to educate the entire automotive workforce on new cyber security practices and to share lessons learned with others.

For more information on companies in this article

Related Content

  • USDOT offers resources to advance deployment of connected vehicles
    May 27, 2016
    A nationwide network of connected vehicles and infrastructure is nearly here. Connected vehicles will be on our roads before the end of the decade. But there's still work to be done to ensure successful deployment and integration of the technology. In June, the US Department of Transportation (USDOT) is partnering with ITS America to host an Accelerating Intelligent Transportation Systems (ITS) Deployment Day during ITS America 2016 in San Jose. The free daylong workshop will highlight the USDOT's ITS p
  • New capabilities in Trafficware’s upgraded ATMS
    February 3, 2016
    Trafficware has released version 2.4 of its market-leading central traffic management system ATMS.now, an advanced traffic management system (ATMS), used by hundreds of state and local Departments of Transportation around the US. New capabilities in the latest release include: Enhancements to both Google and Bing maps editor screens; A new reporting engine to optimise report generation; Centralised control of documents to be delivered to ATMS users; Performance improvements to increase response times in
  • BlackPepper delivers seamless user experience for Resonate platform
    March 29, 2018
    UK-based BlackPepper Software (BlackPepper) has deployed one of its experts to assist Resonate’s in-house team in developing a framework for user experience (UX) consistency for its Luminate digital platform. The solution is designed with the intention meeting the demands of emerging global trends in transport. Luminate is said to provide users with competitive advantages by creating the foundation for a suite of progressive products to meet the demands of machine learning, connected devices, cloud
  • V2V capabilities to feature in over half of cars sold by 2022, say researchers
    May 19, 2017
    A new report from Juniper Research has revealed that, by 2022, 50 per cent of new vehicles will be shipped with vehicle-to-vehicle (V2V) hardware, a technology that enables real-time short-range communication between vehicles. The new research, Consumer Connected Cars: Applications, Telematics & V2V 2017-2022, found that the total number of V2V-enabled consumer vehicles on the road will reach 35 million by 2022, up from less than 150,000 vehicles in 2017. This strong growth rate (376 per cent CAGR) reflects