Skip to content

Annex F: TSA mDL Final Rule Mapping

AI-Generated — Awaiting Review

This section was generated by AI and has not yet received human review. Remove this notice after subject-matter expert sign-off.

This annex maps the technical and organizational security requirements of the TSA mDL Final Rule (6 CFR Part 37, 89 FR 85340, effective November 25, 2024) to SEDI Implementation Guide requirements. This mapping is informative and supports alignment between the SEDI program and federal mDL acceptance standards.

The TSA rule establishes waiver-based requirements for states seeking federal acceptance of mobile driver's licenses. While SEDI is broader than mDL, the rule's organizational security framework, NIST references, and auditor requirements are directly applicable to SEDI infrastructure.

Scope of This Mapping

Included: Technical requirements, organizational security (Appendix A), NIST standards, auditor requirements, incident response.

Excluded: AAMVA-specific namespace requirements, ISO 18013-5 format specifics (those belong in conformance profiles), budget/fiscal estimates, REAL ID Act specific provisions.

NIST Standards Referenced by TSA Rule

The TSA rule incorporates these NIST standards, all of which are relevant to SEDI:

Standard Description SEDI Application
SP 800-53 Rev. 5 Security and Privacy Controls Primary control catalog for organizational security requirements
SP 800-57 Parts 1-3 Key Management Key lifecycle management for SEDI credential infrastructure
SP 800-63-4 Digital Identity Guidelines Identity proofing assurance levels (already normative in Ch. 6)
NIST CSF v1.1 Cybersecurity Framework Organizational cybersecurity posture assessment
FIPS 140-3 Cryptographic Module Validation Key storage hardware requirements
FIPS 186-5 Digital Signature Standard Approved signing algorithms

Provisioning Security Requirements

TSA Requirement CFR Cite SEDI Requirement Notes
Encrypt data in transit and at rest during provisioning 37.10(a)(1)(i) SEDI-SDI-14, SEDI-WAL-02 Applies to both Department and wallet provider
Review repeated failed provisioning attempts 37.10(a)(1)(ii) SEDI-SDI-01 Compromise detection
Confirm applicant controls the device 37.10(a)(1)(iii) SEDI-SDI-04 Device/holder binding
Confirm applicant possesses device private key 37.10(a)(1)(iv) SEDI-CRY-02 Key binding assurance
Prevent false matching with other individuals 37.10(a)(1)(v) SEDI-IDP-04 Identity proofing integrity
Presentation attack detection (liveness) 37.10(a)(1)(vi) SEDI-IDP-04 Anti-spoofing
Data matches authoritative source 37.10(a)(1)(viii) SEDI-SDI-16 Endorsed attribute verification

Organizational Security Requirements (Appendix A)

The TSA rule's Appendix A defines 8 categories of organizational security requirements for mDL issuance infrastructure. These map to SEDI as follows:

# Category What It Covers SEDI Domain
1 Certificate Lifecycle Governance, change mgmt, patching KMS, ORG-07
2 Access Management Least privilege, MFA, account review ORG-01
3 Facility Controls Physical access, supply chain SDI-13, SDI-14
4 Personnel Security Screening, training, termination ORG-02
5 Technical Controls Network segmentation, HSMs, key ceremonies KMS-02, KMS-03
6 Threat Detection Continuous monitoring, log integrity ORG-04
7 Logging Event logging, 36-month retention ORG-04
8 Incident Response Alerting, vuln scanning, pen testing, 72-hr reporting ORG-03, ORG-05

Auditor Requirements

The TSA rule specifies auditor qualifications that can inform SEDI's Expert (EXPT) verification method:

TSA Requirement SEDI Adaptation
CPA license in issuing state Licensed professional in relevant jurisdiction
CISA or CITP certification Information systems security audit certification
Independent of the issuing agency Independent of the Department and wallet providers being assessed
Experienced with information systems security audits Demonstrated experience with digital identity / credential systems
Conflict of interest disclosure and mitigation Same

Key Differences from SEDI

Area TSA mDL Rule SEDI
Credential format ISO 18013-5 (mDoc) only Technology-neutral; format determined by profiles
Anti-surveillance Not addressed Statutory mandate (63A-20-301(3))
Selective disclosure Not addressed Statutory mandate (63A-20-301(1)(e))
Holder control Limited (state-issued credential) Extensive (bill of rights, holder sovereignty)
Scope Federal acceptance of state mDLs State-endorsed digital identity (broader)
Phase Phase 1 waiver; Phase 2 pending Comprehensive from inception

Reference

Full rule text: 89 FR 85340 (October 25, 2024).