FedRAMP 20x is handing a lot of compliance work to machines. Scanners watch the system, pipelines change it, and scripts write the paperwork.
What’s left for the people? A lot, actually. The most important stuff.
John Boyd was an Air Force fighter pilot turned military strategist. His OODA loop runs observe, orient, decide, act. In his 1995 briefing The Essence of Winning and Losing, he drew it with orientation in the middle like a knot. Into it feed five inputs, among them previous experience, new information, and the ongoing work of analysis and synthesis. Out of it run two kinds of arrows. One, labeled “feed forward,” goes to Decision, which Boyd marked as a hypothesis. The others, labeled “implicit guidance and control,” never pass through Decision at all. One runs straight to Action, which Boyd marked as a test. Another runs back to Observation, so orientation shapes what gets noticed in the first place.
Figure 1: Boyd’s OODA sketch from The Essence of Winning and Losing (1995), simplified and redrawn. Orientation shows three of Boyd’s five inputs.
The knot matters because most of what an expert does never passes through a deliberate decision. It passes through what they’ve already learned.
I believe that sketch describes the hinge that determines how successful 20x will ultimately be.
A loop inside the loop
There’s an older model from information science, usually credited to Russell Ackoff, called DIKW, where data becomes information, information becomes knowledge, and knowledge becomes wisdom. I add a different last rung, action. In security, a ladder that doesn’t end in doing something is just a very tall bookshelf.
DIKWA runs inside OODA, and most of it runs inside orientation. Observation hands over raw data. Orientation works that data up into information, then into knowledge, and at its center, into wisdom. Decision commits that wisdom to a course of action. Then the outer loop acts on the world, the world answers, and observation starts again.
The inner loop also turns much faster than the outer one. Take one outer cycle, say the stretch between a vulnerability landing in CISA’s Known Exploited Vulnerabilities catalog and a provider’s affected systems being fixed. Inside it, the inner loop may turn thousands of times. Each turn is a finding enriched, a pattern matched, a case routed, or a question sent back for more data. That difference in tempo matters, and I’ll come back to it.
Figure 2: The DIKWA loop nested inside OODA
Each rung of the inner loop is a different kind of problem. Two of them, turning data into information and carrying wisdom into action, are engineering problems we largely know how to solve. One, turning information into knowledge, is a problem of representation, and it’s the hardest thing in the stack. The last, turning knowledge into wisdom, is where we humans sit.
Data into information
Information is data sorted into patterns. A log line is data. “Every storage bucket blocks public access” is information. Key Security Indicators are pattern statements of exactly this kind, and this is the rung where 20x is most at home.
In How to Assess Risk in 15 Minutes, I borrowed Gen. Stanley McChrystal’s three-part model of assessment from Risk: A User’s Guide, which pairs a quantitative assessment and a qualitative assessment with a mature judgment. The quantitative part belongs on this rung. Point Prowler at a cloud account and you have a structured picture of its configuration in minutes. When I got my Tai Chi app audit-ready, the scanner turned raw configuration into 33 failed checks. Generator scripts turned the live Terraform state into a security plan, a POA&M, and a vulnerability report. I wrote the scripts, and the scripts write the documents.
This rung is solved in principle and unevenly solved in practice. The gap is adoption, which is the whole case for treating GRC engineering as engineering.
Information into knowledge
Knowledge is knowing whether a pattern matters here, and that answer never lives in the pattern itself.
The same critical CVE can appear in two systems. In one, the vulnerable code path is unreachable and the component sits behind three layers of segmentation. In the other, it’s exposed to the internet and sits next to benefits payment data. The information is identical, but the knowledge is opposite. Purl and CPE tell you where to look, CVE and CWE tell you what’s broken, and VEX statements, the KEV catalog, and EPSS scores start to tell you whether it matters here. Past that point, the context is qualitative. This is McChrystal’s second leg, a practitioner at the command line pulling on whatever looks off. Are the tags meaningful? Is the incident comms tree actually out of band? Knowing which thread to pull is a skill, not a query. Some context isn’t in any feed at all. What does this system mean to the mission, and who gets hurt if it goes down?
This is why I think mapping is the best tool we have for turning information into knowledge. People reason about what they can see. A map puts patterns in relation to one another, and that’s where context comes from. Four hundred passing indicators are information. A map showing that the one failing indicator sits on the only internet-facing path into sensitive data is very close to knowledge.
Boyd adds a warning here. In his sketch, orientation also shapes observation; that’s the implicit guidance arrow running back to Observe. The map you carry decides what you go looking for. In 20x terms, the indicators we choose to measure are themselves a product of orientation. A wrong map doesn’t just misread the data. It collects the wrong data in the first place.
Maps fail in two other ways, and 20x is exposed to both. The first is that they don’t compose. When every provider names components differently, an Authorizing Official asking “where am I exposed to this CVE?” across twenty systems gets twenty maps drawn in twenty projections. They look comparable and aren’t. That’s the inventory problem, and it’s a knot of its own. Shared identifiers are how it gets solved. The second failure is older. Borges wrote of cartographers who drew a map the exact size of the empire, and later generations left it in tatters in the desert. Baudrillard went further and described a map that comes before the territory and ends up standing in for it. In compliance, that’s the dashboard that becomes the thing being managed. The defense is to make the map a byproduct of what’s actually running, generated and signed rather than written. Even then, Boyd’s 1976 essay Destruction and Creation is right that every model eventually drifts from what it describes.
Many knots, one mission
So far I’ve drawn one person turning information into knowledge. At scale, there are many. Put an Authorizing Official, an engineer, a CEO, and an auditor in front of the same failing indicator. The engineer sees a configuration change and a pull request. The AO sees mission risk. The CEO sees a customer, a contract, and possibly a board meeting. The auditor sees a gap in the evidence. None of them is wrong. Each brings their own training and experience to the same data, and each runs their own inner loop on it.
Figure 3: One knot per role, converging on a shared mission
Four orientations are only as useful as their ability to converge, and they can’t converge from four different maps. Shared identifiers and a shared inventory are what put everyone in front of the same picture to begin with.
Boyd had an answer for convergence too. In Organic Design for Command and Control (1987), he argued that good command runs on what doesn’t need to be said. People who build similar pictures of the world form “bonds of implicit communications and trust,” and those bonds let them serve a higher-level intent without explicit coordination. A year earlier, in Patterns of Conflict, he described the German idea of a mission as a contract. The subordinate agrees to serve the superior’s intent, and the superior agrees to leave the subordinate wide freedom in how. Chet Richards, one of the editors of Boyd’s briefings, uses the German word Einheit for the mutual trust and unity underneath all this. The practice built on it is Auftragstaktik, and the U.S. Army’s mission command doctrine draws on it. The leader states the intent, and the people closest to the problem decide how to meet it. Authority is narrow. Intent is shared. Execution is distributed.
That’s why the Decide zone in Figure 3 is drawn as a region. It holds a set of decisions. The provider decides to remediate. The AO decides whether to accept a risk. The CEO decides what gets funded first. The auditor decides whether the evidence holds up. They pull toward one decided outcome, and that outcome is the mission.
The four policy types I’ll get to in “Wisdom into action” are the plumbing that makes the convergence work. Most cases never reach the Decide zone at all. The immutable, threshold, and decision channels settle them on the way, and only what’s new or contested escalates to the people who have to converge by hand.
Cybernetics is the science of steering, and it can serve democracy or domination. Norbert Wiener, who named the field, saw that early. In the 1954 revision of The Human Use of Human Beings, he warned that cybernetic machines, “though helpless by themselves, may be used by a human being or a block of human beings to increase their control over the rest of the human race.” Stafford Beer tried to build the democratic version. From late 1971 until the coup of September 1973, Project Cybersyn set out to help Salvador Allende’s government steer Chile’s nationalized industries, with mechanisms meant to preserve individual liberty inside that control. Beer made the case for it in Designing Freedom (1974), and Eden Medina’s Cybernetic Revolutionaries (2011) tells the whole story, including how little the workers it was meant to empower ever got to use it. The difference comes down to whether the decided outcome is shared widely or narrowly.
The obvious objection is that authoritarian systems claim shared intent too. They all do. I believe two things separate them. The federal mission is set through democratic institutions, by people who can be voted out. And every decision in the loop is a hypothesis, tested against reality and written down in a Security Decision Record or a POA&M. Recorded intent can be checked against what happened. Professed intent can only be believed.
In 20x, the authority to decide stays with the AO, and it should. The outcome belongs to the mission and to everyone serving it.
Knowledge into wisdom
Wisdom answers a different question: what should we do?
Knowledge tells you the failing indicator sits on an exposed path to sensitive data. Wisdom decides among the options. You could pull the system offline tonight. You could accept a compensating control for thirty days. You could re-architect ingress next quarter. Choosing means weighing the mission, the cost, the timing, the politics, and the people. McChrystal calls this mature judgment, and in my experience it’s the hardest part of the job. It’s a gut call about whether a team can be trusted to own the outcome. It’s informed by history, but it can’t be reduced to it.
Look again at two of the inputs Boyd put inside orientation, previous experience and the ongoing work of analysis and synthesis. Judgment is built there, by doing the work and then thinking hard about how it went. Boyd called the result fingertip feel. I believe some version of it exists in any living thing that has had to choose between competing goods, though I hold that as a conviction rather than a finding.
What I’m more confident about is what happens when we try to automate this rung. An agent optimizes toward the measurement, not toward what the measurement was meant to capture. That’s Goodhart’s Law running at machine speed. An autonomous system can make every indicator green through a series of insecure decisions that nobody measured. The dashboard stays green until the breach, which is the first contact with reality in a long while.
There’s an old story about this temptation. At Gordium, a prophecy promised the world to whoever could untie a knot binding an ancient ox-cart. Alexander tried, failed, drew his sword, cut it, and declared the prophecy fulfilled. It’s usually told as a lesson in bold thinking. Read it again as a compliance story. He couldn’t meet the condition, so he changed what counted as meeting it and claimed the win. (One ancient account says he simply pulled the pin from the yoke instead, a reminder that even our founding myths come with contested maps.) Some knots do deserve the sword. The inventory problem is one. The market has spent a decade trying to untie it, and a published schema would cut it cleanly. Orientation is a different kind of knot. Standards can be imposed by fiat. Judgment can’t, because it’s made of the person. Cut the representation knot. Never the judgment knot.
So “human in the loop” can’t mean a checkbox somewhere in a workflow. In Staying in the Loop, I used the image of a guitarist riding feedback. They don’t stand outside the loop approving each cycle. They stand at the threshold, where the sound could go either way, and steer. That’s where the Authorizing Official belongs in 20x. It also means that human attention is the scarcest resource in the system, and every design decision should be judged by whether it protects that attention or wastes it.
Wisdom into action
The implicit guidance and control arrow, from orientation straight to action, is how an expert pilot moves without deliberating. Policy-as-code is the institutional version of that arrow, judgment that has already been exercised and compiled into rules.
In while true: manage_risk() I described four kinds of policy. Each one fits a place on this arrow:
- Immutable policies encode judgment so settled it no longer needs discussion. Unencrypted sensitive data doesn’t go in an internet-reachable store, and the pipeline simply refuses it.
- Threshold policies encode a risk tolerance someone already set. Inside the range, the system acts on its own.
- Decision policies apply precedent. Precedent is recorded wisdom rather than wisdom itself, and it holds only as long as the present keeps resembling the past.
- Escalation policies are the explicit path through Decide. They notice when a case has left the territory of prior decisions, gather its context, and put it in front of a person.
In other words, automated triage delivers judgment. It carries a small number of human decisions across thousands of findings, and it saves human attention for the cases that are actually new. The artifacts for writing that judgment down already exist. The 20x Security Decision Record documents how each indicator is met and how that’s verified, and a POA&M records the decisions that aren’t finished yet. When I logged POAM-025 on my own app (virtual MFA in place, hardware key not yet enrolled, compensating control and planned fix recorded), the judgment was mine. The tracking wasn’t.
Boyd’s advantage came from cycling faster than his opponent, getting inside the other side’s loop. Mandiant’s M-Trends 2026 estimated the mean time to exploit in 2025 at negative seven days, which means exploitation now routinely arrives before the patch does. In 2018 and 2019, Mandiant measured that window at 63 days. I expect AI to shrink it further. A provider whose remediation waits on a monthly review board has let the adversary inside its loop. And when exploitation comes before the patch, patching faster can’t close the gap on its own. What gets triaged has to widen to include where the exposure is, which compensating control can go in tonight, and whether anyone would notice the exploitation already underway. Triage is how a provider gets back ahead. Settled questions move at machine speed, and only new questions wait for a person.
A practitioner’s hard-earned wisdom
Start by generating information instead of writing it. Any document a person authors by hand will drift from the system it describes. Derive every artifact from live state, and fail the deploy when they disagree.
Spend most of your effort on representation. Name components the way everyone else names them, so your map can be laid over an agency’s other maps. Build views that show relationships, such as exposure paths, dependencies, and blast radius, rather than counts of passes and fails. Capture the qualitative context that no scanner will find, like mission impact, data sensitivity, and business criticality, as descriptors on the components themselves, so the map can carry it.
Treat escalation as an output worth watching. If almost nothing escalates, your thresholds are probably quietly making decisions that belong to a person. If everything escalates, you’ve buried the one person whose judgment the system exists to protect. Record every human decision, with its reasoning, as data, so the next similar case can be triaged and the one after that can be audited.
And keep McChrystal’s other two legs strong. 20x is very good at the quantitative leg. Every so often, have someone who knows the system look at a passing indicator and ask whether it’s passing for the right reason.
Governance is wisdom applied at scale
In my view, FedRAMP 20x gives us better observation than federal compliance has ever had, and an action pipeline faster than any compliance team in history. Both ends of the loop are becoming machine work. The knot in the middle is not, and it shouldn’t be.
A well-built 20x program gives the person standing in that knot a true picture and brings them only the decisions that are really theirs, then carries out what they decide faster than the adversary can adapt. When there are many people standing in many knots, as in Figure 3, it gives them one map to start from and one mission to converge on.
Boyd marked decision as a hypothesis and action as a test. Every turn of the loop is an experiment about what’s true and what matters. Machines can run the experiment. Someone still has to know what it’s for.
References
- Ackoff, R. L. (1989). “From Data to Wisdom.” Journal of Applied Systems Analysis 16, 3–9.
- Arrian. Anabasis of Alexander, 2.3; Plutarch. Life of Alexander, 18. (Both give Aristobulus’s version, in which Alexander pulls the pin from the yoke.)
- Baudrillard, J. (1981). Simulacres et Simulation. Galilée. English translation: Simulacra and Simulation (1994), University of Michigan Press.
- Beer, S. (1974). Designing Freedom. CBC Learning Systems. (The 1973 CBC Massey Lectures.)
- Borges, J. L. (1946). “Del rigor en la ciencia.” Los Anales de Buenos Aires 1(3). English translation: “On Exactitude in Science,” in Collected Fictions (1998), trans. Andrew Hurley, Viking.
- Boyd, J. R. (1976). Destruction and Creation. Unpublished paper, 3 September 1976.
- Boyd, J. R. (1986). Patterns of Conflict. Briefing, December 1986.
- Boyd, J. R. (1987). Organic Design for Command and Control. Briefing, May 1987.
- Boyd, J. R. (1995). The Essence of Winning and Losing. Briefing, 28 June 1995. John Boyd Collection, Marine Corps University.
- Goodhart, C. A. E. (1975). “Problems of Monetary Management: The U.K. Experience.” Papers in Monetary Economics, Vol. I. Reserve Bank of Australia. The familiar wording, “when a measure becomes a target, it ceases to be a good measure,” is Marilyn Strathern’s (1997).
- Mandiant (Google Cloud). (2024). “How Low Can You Go? An Analysis of 2023 Time-to-Exploit Trends.”
- Mandiant (Google Cloud). (2026). “M-Trends 2026: Data, Insights, and Strategies From the Frontlines.”
- McChrystal, S., & Butrico, A. (2021). Risk: A User’s Guide. Portfolio.
- Medina, E. (2011). Cybernetic Revolutionaries: Technology and Politics in Allende’s Chile. MIT Press.
- Richards, C. (2004). Certain to Win: The Strategy of John Boyd, Applied to Business. Xlibris.
- Wiener, N. (1950). The Human Use of Human Beings: Cybernetics and Society. Houghton Mifflin. Revised edition (1954), Doubleday Anchor; the passage quoted here is from the revised edition.
- Aydlette, S. Article 17, 19, 22, 25, 27, 28, and “Staying in the Loop.” samaydlette.com.