Three senses of “machine-automatable”
“Machine-automatable” means three different things — a property of the control, a fact about the KSI graph, or a rule that mandates automation — and most confusing FedRAMP conversations are two people using two of them.
Ask “how many controls are machine-automatable?” and you can mean three different things, with wildly different answers. Most confusing FedRAMP conversations — and most over-claiming products — are two people using two different senses of the same word without noticing. Hold them apart and you can resolve the argument by restating the question.
Sense 1 — Collectable. Can a machine collect probative evidence for this control? A property of the control's subject matter. No authority publishes the list — any number here is somebody's triage.
Sense 2 — Indicator-reached. Has FedRAMP defined a Key Security Indicator over it? A hard, checkable fact of the KSI graph. A baselined control no indicator reaches is an indicator orphan.
Sense 3 — Automation-mandated. Does a rule require automation as such, independent of which controls are in scope? These rules are per class and they are where the real automation obligation lives.
Sense 2 is the only one that is a checkable fact — the edges are in the dataset and /coverage counts them live. Sense 1 is always somebody’s triage, and an honest one says so. Sense 3 is where the real obligation lives, and it gets its own step. Now sort nine statements — the drill is the step: