Skip to main content

US DOT issues federal guidance for improving motor vehicle cyber security

The US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security. The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised ident
October 25, 2016 Read time: 2 mins
The 324 US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security.

The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised identification and protection of critical vehicle controls and consumers' personal data. Further, it recommends that companies should consider the full life-cycle of their vehicles and facilitate rapid response and recovery from cyber security incidents.

This guidance also highlights the importance of making cyber security a top leadership priority for the automotive industry, and suggests that companies should demonstrate it by allocating appropriate and dedicated resources, and enabling seamless and direct communication channels though organisational ranks related to vehicle cyber security matters.

"Cyber security is a safety issue, and a top priority at the Department," said US Transportation Secretary Anthony Foxx. "Our intention with today's guidance is to provide best practices to help protect against breaches and other security failures that can put motor vehicle safety."

"In the constantly changing environment of technology and cyber security, no single or static approach is sufficient," said NHTSA Administrator Dr Mark Rosekind. "Everyone involved must keep moving, adapting, and improving to stay ahead of the bad guys."

In addition to product development, the guidance suggests best practices for researching, investigating, testing and validating cyber security measures, NHTSA recommends the industry self-audit and consider vulnerabilities and exploits that may impact their entire supply-chain of operations. The safety agency also recommends employee training to educate the entire automotive workforce on new cyber security practices and to share lessons learned with others.

For more information on companies in this article

Related Content

  • Here Technologies: location data sharing needs fundamental rethink
    March 7, 2018
    76% of 8,000 individuals surveyed across eight countries feel stressed or vulnerable about sharing their location data, according to a new study by Here Technologies (Here). The report highlighted concerns that companies are abusing public trust in how they gather and use location data, which it claims will mean a fundamental rethink is necessary to help consumers embrace new services such as autonomous cars. The respondents stated that insufficient controls for management of personal data along with
  • Bedfordshire police speed camera proposals ‘unhelpful’
    November 9, 2015
    A UK enforcement expert and the Institute of Advanced Motorists (IAM) have branded as ‘unhelpful’ the proposal by Olly Martins, Police Commissioner for Bedfordshire to use money from speed camera fines to fill a shortfall in police funding. Martins told the Home Affairs Select Committee that the force was ‘stretched to the limit’ and said, "We’ve extensively lobbied the Home Office for fair funding but they haven’t listened and the Chancellor's spending review at the end of the month means we face more c
  • How does transit prepare for the next pandemic?
    November 30, 2020
    Covid-19 has taught us that once-in-a-generation events do actually happen sometimes. But Ronald E. Boénau suggests that transport agencies can prepare for the next pandemic - without exactly preparing for it at all…
  • Highways Agency publishes 2013 ROI report
    January 16, 2014
    Between 2002 and 2012 over US$5.7 billion was invested on substantial capital investment projects to improve the strategic road network in the UK. The Highways Agency has now published its 2013 Post Opening Project Evaluation (POPE) Meta report is now available on the Agency website, which it says represents the most comprehensive evaluation programme of expenditure within UK transport. Detailed appraisals of individual schemes are also carried out before they are put forward for construction. The broa