Annex F: TSA mDL Final Rule Mapping
This annex maps the technical and organizational security requirements of the TSA mDL Final Rule (6 CFR Part 37, 89 FR 85340, effective November 25, 2024) to SEDI Implementation Guide requirements. This mapping is informative and supports alignment between the SEDI program and federal mDL acceptance standards.
The TSA rule establishes waiver-based requirements for states seeking federal acceptance of mobile driver's licenses. While SEDI is broader than mDL, the rule's organizational security framework, NIST references, and auditor requirements are directly applicable to SEDI infrastructure.
Scope of This Mapping
Included: Technical requirements, organizational security (Appendix A), NIST standards, auditor requirements, incident response.
Excluded: AAMVA-specific namespace requirements, ISO 18013-5 format specifics (those belong in conformance profiles), budget/fiscal estimates, REAL ID Act specific provisions.
NIST Standards Referenced by TSA Rule
The TSA rule incorporates these NIST standards, all of which are relevant to SEDI:
|
Standard |
Description |
SEDI Application |
|---|---|---|
|
SP 800-53 Rev. 5 |
Security and Privacy Controls |
Primary control catalog for organizational security requirements |
|
SP 800-57 Parts 1-3 |
Key Management |
Key lifecycle management for SEDI credential infrastructure |
|
SP 800-63-4 |
Digital Identity Guidelines |
Identity proofing assurance levels (already normative in Ch. 6) |
|
NIST CSF v1.1 |
Cybersecurity Framework |
Organizational cybersecurity posture assessment |
|
FIPS 140-3 |
Cryptographic Module Validation |
Key storage hardware requirements |
|
FIPS 186-5 |
Digital Signature Standard |
Approved signing algorithms |
Provisioning Security Requirements
|
TSA Requirement |
CFR Cite |
SEDI Requirement |
Notes |
|---|---|---|---|
|
Encrypt data in transit and at rest during provisioning |
37.10(a)(1)(i) |
SEDI-SDI-14, SEDI-WAL-02 |
Applies to both Department and wallet provider |
|
Review repeated failed provisioning attempts |
37.10(a)(1)(ii) |
SEDI-SDI-01 |
Compromise detection |
|
Confirm applicant controls the device |
37.10(a)(1)(iii) |
SEDI-SDI-04 |
Device/holder binding |
|
Confirm applicant possesses device private key |
37.10(a)(1)(iv) |
SEDI-CRY-02 |
Key binding assurance |
|
Prevent false matching with other individuals |
37.10(a)(1)(v) |
SEDI-IDP-04 |
Identity proofing integrity |
|
Presentation attack detection (liveness) |
37.10(a)(1)(vi) |
SEDI-IDP-04 |
Anti-spoofing |
|
Data matches authoritative source |
37.10(a)(1)(viii) |
SEDI-SDI-16 |
Endorsed attribute verification |
Organizational Security Requirements (Appendix A)
The TSA rule's Appendix A defines 8 categories of organizational security requirements for mDL issuance infrastructure. These map to SEDI as follows:
|
# |
Category |
What It Covers |
SEDI Domain |
|---|---|---|---|
|
1 |
Certificate Lifecycle |
Governance, change mgmt, patching |
KMS, ORG-07 |
|
2 |
Access Management |
Least privilege, MFA, account review |
ORG-01 |
|
3 |
Facility Controls |
Physical access, supply chain |
SDI-13, SDI-14 |
|
4 |
Personnel Security |
Screening, training, termination |
ORG-02 |
|
5 |
Technical Controls |
Network segmentation, HSMs, key ceremonies |
KMS-02, KMS-03 |
|
6 |
Threat Detection |
Continuous monitoring, log integrity |
ORG-04 |
|
7 |
Logging |
Event logging, 36-month retention |
ORG-04 |
|
8 |
Incident Response |
Alerting, vuln scanning, pen testing, 72-hr reporting |
ORG-03, ORG-05 |
Auditor Requirements
The TSA rule specifies auditor qualifications that can inform SEDI's Expert (EXPT) verification method:
|
TSA Requirement |
SEDI Adaptation |
|---|---|
|
CPA license in issuing state |
Licensed professional in relevant jurisdiction |
|
CISA or CITP certification |
Information systems security audit certification |
|
Independent of the issuing agency |
Independent of the Department and wallet providers being assessed |
|
Experienced with information systems security audits |
Demonstrated experience with digital identity / credential systems |
|
Conflict of interest disclosure and mitigation |
Same |
Key Differences from SEDI
|
Area |
TSA mDL Rule |
SEDI |
|---|---|---|
|
Credential format |
ISO 18013-5 (mDoc) only |
Technology-neutral; format determined by profiles |
|
Anti-surveillance |
Not addressed |
Statutory mandate (63A-20-301(3)) |
|
Selective disclosure |
Not addressed |
Statutory mandate (63A-20-301(1)(e)) |
|
Holder control |
Limited (state-issued credential) |
Extensive (bill of rights, holder sovereignty) |
|
Scope |
Federal acceptance of state mDLs |
State-endorsed digital identity (broader) |
|
Phase |
Phase 1 waiver; Phase 2 pending |
Comprehensive from inception |
Reference
Full rule text: 89 FR 85340 (October 25, 2024).