Risk Management

Risk Management #

How Deevnet decides what can go wrong, what to do about it, and what to accept. It replaces the earlier Security & Vulnerability Management stub: security is one kind of risk, alongside losing state, losing a device, and not being able to explain why something is configured the way it is.

Deevnet is a portable lab run by a small team on consumer hardware. The aim is not to eliminate risk β€” it is to know each risk, choose a treatment deliberately, and write the choice down, so nothing is a surprise.


The cycle #

StepWhat happensWhere it is written
Identifya risk is noticed β€” in design, in a change, in an incident, from an advisoryan ADR’s consequences, a change record, an incident record
Assesshow likely, and how bad if it happensthe risk register
Treatreduce it, transfer it, avoid it, or accept it β€” explicitlya change record (reduce), an ADR (avoid/accept)
Reviewis the treatment still right?the register, when a related change or incident lands

Accepting a risk is a legitimate treatment. Accepting it silently is not.

The areas #

Page last modified: September 23, 2026