Obtain TSA approval before implementing airport security-program amendments

Use 49 CFR 1542.105 -- Airport Security to review this narrow operational decision without extending the source beyond its stated scope.

Integrated video surveillance and controlled entry at a modern commercial facility.
DSE visual intelligencePhysical securityExplainer · 3 min read
Executive summary

What you need to know

Use 49 CFR 1542.105 -- Airport Security to review this narrow operational decision without extending the source beyond its stated scope.

Potentially affected

Teams, systems, services, or facilities within the stated scope of 49 CFR 1542.105 -- Airport Security

DSE recommendation

Compare the observed state with the cited official source, document applicability and exceptions, and test any approved change with rollback safeguards.

Frame this document as a source-led configuration and assurance check: Obtain TSA approval before implementing airport security-program amendments. Only the official source and traced locations below supply facts. Confirm applicability before acting.

Source fact:

The official 49 CFR 1542.105 — Airport Security from Transportation Security Administration via eCFR supports the following bounded statements:

  • Under 49 CFR 1542, the airport operator may either submit a modified security program to the designated official for approval, or petition the Administrator to reconsider the notice to modify within 30 days of receiving a notice to modify. The research record locates this support at 49 CFR 1542.105(a)(2) (eCFR anchor p-1542.105(a)(2)).
  • Under 49 CFR 1542, the designated official, within 30 days after receiving the proposed security program, will either approve the program or give the airport operator written notice to modify the program to comply with the applicable requirements of this part. The research record locates this support at 49 CFR 1542.105(a)(1) (eCFR anchor p-1542.105(a)(1)).

Do not import neighboring assumptions into the source record. The supported task is a scoped comparison involving access control, video, intrusion detection, communications, supporting facilities, operators, and documented response paths and the conditions the source actually describes.

What the source does not establish

Applies only to airport operators, tenants, personnel, and areas covered by 49 CFR part 1542 and the cited section. Confirm the TSA-approved security program and current directives; this is not legal advice or a universal access-control standard. The citation is not a substitute for observed state, authorization, compliance evidence, or dependency health. Examine identity, Windows DNS where used, time, networks, power, life-safety systems, vendors, and monitoring personnel before translating the source into an operational decision.

Applicability questions

  • For source statement 1 at 49 CFR 1542.105(a)(2) (eCFR anchor p-1542.105(a)(2)), which observable configuration, record, or test can confirm applicability here?
  • For source statement 2 at 49 CFR 1542.105(a)(1) (eCFR anchor p-1542.105(a)(1)), which observable configuration, record, or test can confirm applicability here?
  • Which owner can attest to the recorded state of access control, video, intrusion detection, communications, supporting facilities, operators, and documented response paths, including exceptions?
  • What baseline for identity, Windows DNS where used, time, networks, power, life-safety systems, vendors, and monitoring personnel must accompany the source-specific observation?
  • Which success, stop, and escalation criteria are written before testing begins?

DSE recommendation:

DSE recommends using the cited source as the evidence anchor for this decision. Use a two-person review for the source interpretation and the resulting operational decision. Record the source location, examined part of access control, video, intrusion detection, communications, supporting facilities, operators, and documented response paths, observed and expected states, owner, and reason for deviation.

Do not move from citation to production in one step. Pilot the decision where practical, observe agreed signals, retain a reversal point, and verify identity, Windows DNS where used, time, networks, power, life-safety systems, vendors, and monitoring personnel. Handle credentials, keys, recovery data, and personal information through approved secure channels.

Verification and evidence

Keep the source locations 49 CFR 1542.105(a)(2) (eCFR anchor p-1542.105(a)(2)); 49 CFR 1542.105(a)(1) (eCFR anchor p-1542.105(a)(1)) adjacent to the sanitized artifacts used for comparison. Prefer asset and firmware inventories, configuration exports, event tests, inspections, alarm response records, and maintenance findings, with enough identity and timing data for an independent recheck.

Retain the starting state, authorization, execution record, outcome, deviation, and final state as one review package. Move disruptive checks to an approved test path. Reopen the decision when versions, design, dependencies, ownership, or official guidance changes.

Official references

Primary reference

Review the official source

49 CFR 1542.105 -- Airport Security · Verified August 26, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE