This document outlines a two-level feedback control architecture for intrusion tolerance in networked systems. At the local level, node controllers monitor individual replicas and make recovery decisions based on belief states about their health. At the global level, a system controller scales the replication factor based on belief state information from the node controllers. The architecture provides correct service if certain conditions are met, including maintaining a sufficient number of replicas. The two-level approach models intrusion tolerance as classical machine replacement and inventory replenishment control problems.