Skip to main content

US DOT issues federal guidance for improving motor vehicle cyber security

The US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security. The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised ident
October 25, 2016 Read time: 2 mins
The 324 US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security.

The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised identification and protection of critical vehicle controls and consumers' personal data. Further, it recommends that companies should consider the full life-cycle of their vehicles and facilitate rapid response and recovery from cyber security incidents.

This guidance also highlights the importance of making cyber security a top leadership priority for the automotive industry, and suggests that companies should demonstrate it by allocating appropriate and dedicated resources, and enabling seamless and direct communication channels though organisational ranks related to vehicle cyber security matters.

"Cyber security is a safety issue, and a top priority at the Department," said US Transportation Secretary Anthony Foxx. "Our intention with today's guidance is to provide best practices to help protect against breaches and other security failures that can put motor vehicle safety."

"In the constantly changing environment of technology and cyber security, no single or static approach is sufficient," said NHTSA Administrator Dr Mark Rosekind. "Everyone involved must keep moving, adapting, and improving to stay ahead of the bad guys."

In addition to product development, the guidance suggests best practices for researching, investigating, testing and validating cyber security measures, NHTSA recommends the industry self-audit and consider vulnerabilities and exploits that may impact their entire supply-chain of operations. The safety agency also recommends employee training to educate the entire automotive workforce on new cyber security practices and to share lessons learned with others.

For more information on companies in this article

Related Content

  • ITS America statement on FCC proposed spectrum sharing
    January 21, 2013
    In response to recent comments by FCC Chairman Julius Genachowski, and the ongoing study of spectrum sharing being undertaken by the National Telecommunications and Information Administration, the Intelligent Transportation Society of America (ITS America) urged spectrum policymakers not to fast track a decision on opening the 5.9 GHz band to unlicensed users. A complete record and fair opportunity for all affected parties to participate in the process needs to be addressed, particularly since life-saving v
  • Two former secretaries of transportation speak at ITS America San Jose
    June 13, 2016
    Not one, but two former US Secretaries of Transportation will be on stage during keynote addresses tomorrow and Wednesday to talk about their leadership during critical times in recent history. Norman Y. Mineta gave the unprecedented order to ground all civilian air traffic
  • First electric buses hit London’s streets
    December 19, 2013
    Transport for London (TfL) and bus operator Go-Ahead London have begun a trial of the capital’s first electric buses on two routes in the city. The 12-metre single deck buses were built by Chinese manufacturer BYD Auto have zero tail pipe emissions, resulting in lower carbon emissions. The trial will help TfL develop plans for greater use of electric buses in central London in the future, supporting the Mayor’s vision of a central London Ultra Low Emission Zone. The trial will be used to establish wh
  • Xerox Achieves ISO 9001 Quality Management System certification
    March 7, 2014
    Following a multi-location assessment of seven work sites Xerox’s Government and Transportation Sector Technology Delivery Center (GTS TDC) has achieved ISO 9001:2008 Quality Management System certification. Xerox GTS TDC designs, develops and delivers technology transportation solutions in electronic tolling, parking, photo enforcement, fare collections and management, and computer-aided dispatch/automatic vehicle location (CAD/AVL) systems. The assessment found that Xerox GTS TDC yielded ‘zero nonco