Skip to main content

US DOT issues federal guidance for improving motor vehicle cyber security

The US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security. The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised ident
October 25, 2016 Read time: 2 mins
The 324 US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security.

The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised identification and protection of critical vehicle controls and consumers' personal data. Further, it recommends that companies should consider the full life-cycle of their vehicles and facilitate rapid response and recovery from cyber security incidents.

This guidance also highlights the importance of making cyber security a top leadership priority for the automotive industry, and suggests that companies should demonstrate it by allocating appropriate and dedicated resources, and enabling seamless and direct communication channels though organisational ranks related to vehicle cyber security matters.

"Cyber security is a safety issue, and a top priority at the Department," said US Transportation Secretary Anthony Foxx. "Our intention with today's guidance is to provide best practices to help protect against breaches and other security failures that can put motor vehicle safety."

"In the constantly changing environment of technology and cyber security, no single or static approach is sufficient," said NHTSA Administrator Dr Mark Rosekind. "Everyone involved must keep moving, adapting, and improving to stay ahead of the bad guys."

In addition to product development, the guidance suggests best practices for researching, investigating, testing and validating cyber security measures, NHTSA recommends the industry self-audit and consider vulnerabilities and exploits that may impact their entire supply-chain of operations. The safety agency also recommends employee training to educate the entire automotive workforce on new cyber security practices and to share lessons learned with others.

For more information on companies in this article

Related Content

  • ETSC welcomes EU study on speed limitation devices
    November 11, 2013
    The European Traffic Safety Council (ETSC) has welcomed the publication of a European Commission study which evaluates the effects of the implementation of Directive 92/6/EEC on speed limitation devices. The study recommends, as ways of improving the Directive’s effectiveness, exploring the options of introducing intelligent speed assistance (ISA) to the vehicles currently covered by the legislation, as well as extending its requirements to some light commercial vehicles. “ETSC welcomes today’s publicati
  • Van driver banned for ignoring motorway incident road block
    October 18, 2018
    A van driver who ignored a Highways England road block on the UK’s M42 motorway has been banned from driving for six months. The case highlights the need for incident zone safety: the road block had been put in place by traffic officers following a fatal crash. Richard Leonard, head of road safety at Highways England, said: “We hope this case sends out an important message because those who ignore road closures put other people’s safety in jeopardy and this was clearly the case here for our traffic officers
  • Australia trials shortened cost benefit evaluation
    January 13, 2017
    A shortened and tailored cost benefit assessment is helping show the worth of C-ITS in Australia. An Australian ‘rapid cost-benefit assessment’ method, introduced to help prepare the ground for co-operative ITS (C-ITS) deployment and showcased at the ITS World Congress in Melbourne, has generated encouraging results.
  • Traffic accidents ‘number one worldwide cause of death among the young’
    October 31, 2014
    A new study released by the Allianz Center for Technology (AZT) found that traffic accidents are the leading cause of death for youths, regardless of a country’s economic well-being. Thirty-one percent of all traffic-related deaths in the world are youth and young adults aged between 15 and 29 years. This translates to more than 400,000 lives lost per year, which exceeds youth deaths caused by diseases, drug use, suicide, violence or war-related events. Whether a traffic-related death of a youth occurs i