Class A Role Appointments — DZTE

Date: September 14, 2026 Author: Dean Macris From: Dean Macris, System Owner To: Grady Houston, Robert Jamison, Carlos Salas, Paul Carbonell, Ethan Schmertzler, Security Team Subject: Designation of Key Personnel for the FedRAMP 20x Class A Certification of Dispel Zero Trust Engine (DZTE)
Download PDF Controlled copy — valid on date of download only

Purpose

This memo designates the key personnel responsible for core program functions supporting the FedRAMP 20x Class A certification of the Dispel Zero Trust Engine (DZTE), and records one appointment that supersedes the Rev5 System Security Plan.

It is issued under the System Owner’s duty, stated in the DZTE SSP §2.2.1, to “designate key personnel as responsible for core program functions.”

Background

The Rev5 SSP package (v1.3, 6 January 2026) names four individuals across 1,634 pages. Its role section defines exactly two roles by name — System Owner and ISSO. Every other role appears only as a control-parameter title with no named holder: AC-2(h) assigns account actions to an “Identity and Access Management Administrator,” and AC-6(1) names “Security Operations personnel,” neither with a person behind it.

FedRAMP 20x Class A, and the DZTE compliance platform that prepares the submission, require a named, active primary holder for each role. That is a stricter bar than the Rev5 package met. The platform’s own submission-readiness check currently reports three role gaps as blocking certification.

This memo closes them.

Key Points

Appointments

RoleAppointeeStatus
System Owner (SO)Dean Macris, Chief Information Security OfficerUnchanged from Rev5
Information System Security Officer (ISSO)Grady HoustonNEW — supersedes Rev5
Privacy OfficerEthan SchmertzlerUnchanged from Rev5
Identity & Access Management AdministratorRobert JamisonNEW — appointed 2026-09-14
Vulnerability ManagerCarlos SalasNEW — appointed 2026-09-14

The ISSO appointment supersedes the Rev5 package

The Rev5 SSP names Paul Carbonell as ISSO in Table 5.1 and states the ISSO “has been appointed in writing and is deemed to have significant cyber security and operational role responsibilities.”

Effective with this memo, the ISSO for DZTE is Grady Houston. This memo is that appointment in writing. Paul Carbonell’s prior service in the role is gratefully acknowledged and he remains the compliance owner for KSI scope and boundary decisions.

Responsibilities the ISSO inherits immediately

Two are already recorded as architectural decisions for the Class A submission:

  • Training effectiveness (KSI-CED-RAT). The ISSO is responsible for the effectiveness of the cybersecurity education and training programme, reviewed annually.
  • After-action reports (KSI-INR-AAR). The Incident Response Manager submits the after-action report; the ISSO accepts it. Threshold: incidents of high severity and above, within 30 days of incident closure.

Roles newly designated

Neither could be inherited from Rev5; both were blocking Class A certification readiness.

Now designated: Robert Jamison, as Identity & Access Management Administrator, owning account provisioning, modification and removal actions under AC-2 and the AC-2(h) parameter the Rev5 package left unassigned.

Now designated: Carlos Salas, as Vulnerability Manager, owning the recurring vulnerability detection and response programme and the AC-6(1) “Security Operations personnel” function the Rev5 package left unassigned.

This separates two duties the Rev5 package left blurred. The SSP assigns the System Owner the duty to “provide CSP approval for vulnerability management decisions” — that is an approval role. The Vulnerability Manager operates the programme. Holding both in one person would have collapsed the operator and the approver into a single seat.

Name of record — resolved

The ISSO’s name of record is Grady Houston, confirmed by the System Owner on 2026-09-14.

This is noted because the name had been recorded inconsistently across the platform’s architectural decision records — as “Grady Blair” on six pages, “Grady Houston” on two, and without a surname on thirteen. Grady Houston is correct; the ADR set has been corrected to match. While Grady served only as a reviewer this was a documentation defect; as the named ISSO it is a legal name in a federal submission package, and it is now settled.

Recommendation

Adopt the appointments above. All five roles are now held. This closes the three role gaps the DZTE compliance platform reports as blocking Class A certification readiness — the ISSO primary-holder conflict, the unassigned IAM Administrator, and the unassigned Vulnerability Manager.

Next Steps

  1. Confirm Grady’s full legal name — done 2026-09-14: Grady Houston. ADR set corrected.
  2. Designate the Identity & Access Management Administrator — done 2026-09-14: Robert Jamison.
  3. Designate the Vulnerability Manager — done 2026-09-14: Carlos Salas.
  4. Record all appointments in the DZTE compliance platform as the active primary holder for each role, and remove any superseded primary assignment for the ISSO.
  5. Confirm security@dispel.com — already the documented vulnerability-reporting channel in the Rev5 package — as the FedRAMP Security Inbox, and verify it is reachable without a CAPTCHA, portal login, or other service-specific action.

Signature:

This memo was signed via git commit. Verify authenticity using git log --show-signature

Document Provenance

Last ModifiedSeptember 14, 2026 at 14:34 -0400
AuthorConstantine Macris
Signature Verified Constantine Macris
Commite689821 View on GitHub
File HistoryAll changes