Skip to main content

US DOT issues federal guidance for improving motor vehicle cyber security

The US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security. The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised ident
October 25, 2016 Read time: 2 mins
The 324 US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security.

The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised identification and protection of critical vehicle controls and consumers' personal data. Further, it recommends that companies should consider the full life-cycle of their vehicles and facilitate rapid response and recovery from cyber security incidents.

This guidance also highlights the importance of making cyber security a top leadership priority for the automotive industry, and suggests that companies should demonstrate it by allocating appropriate and dedicated resources, and enabling seamless and direct communication channels though organisational ranks related to vehicle cyber security matters.

"Cyber security is a safety issue, and a top priority at the Department," said US Transportation Secretary Anthony Foxx. "Our intention with today's guidance is to provide best practices to help protect against breaches and other security failures that can put motor vehicle safety."

"In the constantly changing environment of technology and cyber security, no single or static approach is sufficient," said NHTSA Administrator Dr Mark Rosekind. "Everyone involved must keep moving, adapting, and improving to stay ahead of the bad guys."

In addition to product development, the guidance suggests best practices for researching, investigating, testing and validating cyber security measures, NHTSA recommends the industry self-audit and consider vulnerabilities and exploits that may impact their entire supply-chain of operations. The safety agency also recommends employee training to educate the entire automotive workforce on new cyber security practices and to share lessons learned with others.

For more information on companies in this article

Related Content

  • LG’s V2X solution gets Common Criteria certification
    September 25, 2024
    VW Transceiver Module is telematics component for OEM's engine-specific MQB platform
  • Cross border enforcement a logical step
    January 30, 2012
    The logic supporting a cross-border enforcement Directive for the European Union (EU) is both detailed and compelling. The White Paper on European transport policy published in 2001 included the ambitious objective of reducing by 50 per cent by 2010 the number of people killed on the roads of the EU. But since 2005 the reduction in the number of road deaths has been slowing down: overall, the period from 2001 until 2009 saw the number of fatalities decrease by 36 per cent. According to Community indicators,
  • Mixed welcome for Trump’s nomination for US Transportation Secretary
    December 5, 2016
    The Institute of Transportation Engineers (ITE) has welcomed Donald Trump’s nomination of Elaine Chao for Transportation Secretary. "This is a step in the right direction as former labour secretary Chao previously served in key leadership positions at the US Department of Transportation (USDOT) and in the private sector. She realises the challenges facing the transportation system and how it affects individual businesses and communities and the nation as a whole," said Jeffrey F. Paniati, ITE executive
  • Gig economy drivers and riders at increased risk of collisions, warns UCL
    September 3, 2018
    Self-employed courier or taxi drivers who get their work through apps could be more likely to be involved in a collision, says a new study. The University College London (UCL) research found 63% of ‘gig’ economy respondents – who are not paid a salary - are not provided with safety training about managing risks on the road. The emerging issues for management of occupational road risk in a changing economy: A survey of gig economy drivers, riders and their managers also revealed 65% of drivers did not