DREAD Risk Rating Model (Legacy)
Jump to:
Overview
The DREAD Risk Rating Model is a legacy framework used to quantify and prioritize security risks based on five categories: Damage potential, Reproducibility, Exploitability, Affected users, and Discoverability. It assists organizations in systematically assessing threat severity to inform vulnerability management and remediation efforts.
Primary Objectives
- Enable consistent and repeatable risk assessment across security teams
- Benefit security analysts, risk managers, and decision-makers by providing a structured risk prioritization method
- Support informed decision-making and accountability in vulnerability remediation and resource allocation
Scope & Applicability
- Applicable to organizations of various sizes and industries seeking to prioritize security risks
- Covers threat and vulnerability risk assessment but excludes detailed control implementation or compliance requirements
- Requires an established asset inventory and basic understanding of threat scenarios for effective use
Core Structure
- Consists of five risk factors: Damage potential, Reproducibility, Exploitability, Affected users, and Discoverability
- Organized as a scoring model where each factor is rated on a scale, and the aggregate score determines risk severity
- Terminology centers on risk factors rather than formal control IDs or clauses
How It Is Used
- Typically adopted as part of vulnerability assessment or threat modeling processes
- Used in assessment workflows to score identified threats and prioritize remediation efforts
- Supports engineering workflows by informing risk-based decisions during design reviews and security testing
Implementation Artifacts
- Risk assessment templates and scoring sheets derived from the DREAD categories
- May be integrated with vulnerability management tools to track risk scores and remediation status
- Evidence includes documented risk ratings, threat descriptions, and mitigation plans
Measurement & Maturity
- Risk scores serve as key indicators for prioritization but do not measure control effectiveness directly
- No formal maturity model; effectiveness depends on consistent application and integration with broader risk management
- Common baseline involves using DREAD scores to prioritize high-risk vulnerabilities for remediation
Common Pitfalls
- Over-reliance on subjective scoring leading to inconsistent risk ratings
- Applying DREAD without integrating organizational context or asset criticality
- Failure to update risk assessments as threat landscapes evolve, resulting in stale data
Integration & Mapping
- Can complement frameworks like STRIDE for threat modeling or integrate with vulnerability management processes
- Useful in governance, risk, and compliance (GRC) platforms to enhance risk prioritization
- Limited direct mapping to formal control frameworks such as NIST or ISO but supports risk-based control selection
When Not to Use It
- Not suitable as a standalone compliance framework or for organizations requiring regulatory-specific risk assessments
- May be too subjective or granular for high-level executive reporting without additional context
- Lightweight or automated risk scoring tools may be preferred in fast-paced or large-scale environments
Standards & References
- Originally developed by Microsoft as part of threat modeling practices
- Referenced in various security literature and threat modeling guides but lacks formal standardization
- Companion materials include threat modeling methodologies such as STRIDE and risk assessment best practices
More in Threat Models