Class A Role Appointments — DZTE
Purpose
This memo designates the key personnel responsible for core program functions supporting the FedRAMP 20x Class A certification of the Dispel Zero Trust Engine (DZTE), and records one appointment that supersedes the Rev5 System Security Plan.
It is issued under the System Owner’s duty, stated in the DZTE SSP §2.2.1, to “designate key personnel as responsible for core program functions.”
Background
The Rev5 SSP package (v1.3, 6 January 2026) names four individuals across 1,634 pages. Its role section defines exactly two roles by name — System Owner and ISSO. Every other role appears only as a control-parameter title with no named holder: AC-2(h) assigns account actions to an “Identity and Access Management Administrator,” and AC-6(1) names “Security Operations personnel,” neither with a person behind it.
FedRAMP 20x Class A, and the DZTE compliance platform that prepares the submission, require a named, active primary holder for each role. That is a stricter bar than the Rev5 package met. The platform’s own submission-readiness check currently reports three role gaps as blocking certification.
This memo closes them.
Key Points
Appointments
| Role | Appointee | Status |
|---|---|---|
| System Owner (SO) | Dean Macris, Chief Information Security Officer | Unchanged from Rev5 |
| Information System Security Officer (ISSO) | Grady Houston | NEW — supersedes Rev5 |
| Privacy Officer | Ethan Schmertzler | Unchanged from Rev5 |
| Identity & Access Management Administrator | Robert Jamison | NEW — appointed 2026-09-14 |
| Vulnerability Manager | Carlos Salas | NEW — appointed 2026-09-14 |
The ISSO appointment supersedes the Rev5 package
The Rev5 SSP names Paul Carbonell as ISSO in Table 5.1 and states the ISSO “has been appointed in writing and is deemed to have significant cyber security and operational role responsibilities.”
Effective with this memo, the ISSO for DZTE is Grady Houston. This memo is that appointment in writing. Paul Carbonell’s prior service in the role is gratefully acknowledged and he remains the compliance owner for KSI scope and boundary decisions.
Responsibilities the ISSO inherits immediately
Two are already recorded as architectural decisions for the Class A submission:
- Training effectiveness (KSI-CED-RAT). The ISSO is responsible for the effectiveness of the cybersecurity education and training programme, reviewed annually.
- After-action reports (KSI-INR-AAR). The Incident Response Manager submits the after-action report; the ISSO accepts it. Threshold: incidents of
highseverity and above, within 30 days of incident closure.
Roles newly designated
Neither could be inherited from Rev5; both were blocking Class A certification readiness.
Now designated: Robert Jamison, as Identity & Access Management Administrator, owning account provisioning, modification and removal actions under AC-2 and the AC-2(h) parameter the Rev5 package left unassigned.
Now designated: Carlos Salas, as Vulnerability Manager, owning the recurring vulnerability detection and response programme and the AC-6(1) “Security Operations personnel” function the Rev5 package left unassigned.
This separates two duties the Rev5 package left blurred. The SSP assigns the System Owner the duty to “provide CSP approval for vulnerability management decisions” — that is an approval role. The Vulnerability Manager operates the programme. Holding both in one person would have collapsed the operator and the approver into a single seat.
Name of record — resolved
The ISSO’s name of record is Grady Houston, confirmed by the System Owner on 2026-09-14.
This is noted because the name had been recorded inconsistently across the platform’s architectural decision records — as “Grady Blair” on six pages, “Grady Houston” on two, and without a surname on thirteen. Grady Houston is correct; the ADR set has been corrected to match. While Grady served only as a reviewer this was a documentation defect; as the named ISSO it is a legal name in a federal submission package, and it is now settled.
Recommendation
Adopt the appointments above. All five roles are now held. This closes the three role gaps the DZTE compliance platform reports as blocking Class A certification readiness — the ISSO primary-holder conflict, the unassigned IAM Administrator, and the unassigned Vulnerability Manager.
Next Steps
Confirm Grady’s full legal name— done 2026-09-14: Grady Houston. ADR set corrected.Designate the Identity & Access Management Administrator— done 2026-09-14: Robert Jamison.Designate the Vulnerability Manager— done 2026-09-14: Carlos Salas.- Record all appointments in the DZTE compliance platform as the active primary holder for each role, and remove any superseded primary assignment for the ISSO.
- Confirm
security@dispel.com— already the documented vulnerability-reporting channel in the Rev5 package — as the FedRAMP Security Inbox, and verify it is reachable without a CAPTCHA, portal login, or other service-specific action.
Signature:
This memo was signed via git commit. Verify authenticity using git log --show-signature