Skip to main content

US DOT issues federal guidance for improving motor vehicle cyber security

The US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security. The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised ident
October 25, 2016 Read time: 2 mins
The 324 US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security.

The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised identification and protection of critical vehicle controls and consumers' personal data. Further, it recommends that companies should consider the full life-cycle of their vehicles and facilitate rapid response and recovery from cyber security incidents.

This guidance also highlights the importance of making cyber security a top leadership priority for the automotive industry, and suggests that companies should demonstrate it by allocating appropriate and dedicated resources, and enabling seamless and direct communication channels though organisational ranks related to vehicle cyber security matters.

"Cyber security is a safety issue, and a top priority at the Department," said US Transportation Secretary Anthony Foxx. "Our intention with today's guidance is to provide best practices to help protect against breaches and other security failures that can put motor vehicle safety."

"In the constantly changing environment of technology and cyber security, no single or static approach is sufficient," said NHTSA Administrator Dr Mark Rosekind. "Everyone involved must keep moving, adapting, and improving to stay ahead of the bad guys."

In addition to product development, the guidance suggests best practices for researching, investigating, testing and validating cyber security measures, NHTSA recommends the industry self-audit and consider vulnerabilities and exploits that may impact their entire supply-chain of operations. The safety agency also recommends employee training to educate the entire automotive workforce on new cyber security practices and to share lessons learned with others.

For more information on companies in this article

Related Content

  • ITS (UK) Interest Group calls for targeted initiatives on transport emissions
    November 21, 2017
    A more targeted approach to dealing with the automotive industry which has the biggest effect on transport emissions is needed; rather than an overall reduction in average levels of harmful pollutants, according to a meeting held by the ITS (UK) Smart Environment Interest Group. The event featured experts using Intelligent transport systems (ITS) to help improve the environment.
  • TidalWave sweeps over Trafficware’s ATMS 2.10
    June 11, 2020
    New addition to latest iteration of traffic management product
  • Moody’s: Burden of infrastructure spending increasingly falling on US states
    January 24, 2017
    Repairing or replacing aging transportation infrastructure, such as roads and bridges, will require US states to shoulder additional cost burdens since federal funding has stagnated over the last 20 years, Moody’s Investors Service says in a new report. States with large maintenance burdens and backlogs will face budgetary challenges in meeting these needs. US federal highway aid has seen little growth from fiscal 2009-15 and is projected to remain flat when adjusted for inflation through fiscal 2020. Th
  • Automating enforcement of environmental zones
    July 27, 2012
    Amsterdam City Council has chosen to move away from manual enforcement of its environmental zone, which is intended to keep highly polluting goods vehicles out of the city centre, and is installing an automated, ANPR-based system. The signs are not much to look at: white with a red circle and the all-important word Milieuzone ('Environmental zone'). But these signs mean that Amsterdam's city centre is strictly off-limits to polluting goods traffic. At the moment compliance is monitored by special wardens wh