Advisor
Wiki Standards, Frameworks & Models Threat Models DREAD Risk Rating Model (Legacy)

DREAD Risk Rating Model (Legacy)

2 min read
Jump to:

Overview

The DREAD Risk Rating Model is a legacy framework used to quantify and prioritize security risks based on five categories: Damage potential, Reproducibility, Exploitability, Affected users, and Discoverability. It assists organizations in systematically assessing threat severity to inform vulnerability management and remediation efforts.

Primary Objectives

  • Enable consistent and repeatable risk assessment across security teams
  • Benefit security analysts, risk managers, and decision-makers by providing a structured risk prioritization method
  • Support informed decision-making and accountability in vulnerability remediation and resource allocation

Scope & Applicability

  • Applicable to organizations of various sizes and industries seeking to prioritize security risks
  • Covers threat and vulnerability risk assessment but excludes detailed control implementation or compliance requirements
  • Requires an established asset inventory and basic understanding of threat scenarios for effective use

Core Structure

  • Consists of five risk factors: Damage potential, Reproducibility, Exploitability, Affected users, and Discoverability
  • Organized as a scoring model where each factor is rated on a scale, and the aggregate score determines risk severity
  • Terminology centers on risk factors rather than formal control IDs or clauses

How It Is Used

  • Typically adopted as part of vulnerability assessment or threat modeling processes
  • Used in assessment workflows to score identified threats and prioritize remediation efforts
  • Supports engineering workflows by informing risk-based decisions during design reviews and security testing

Implementation Artifacts

  • Risk assessment templates and scoring sheets derived from the DREAD categories
  • May be integrated with vulnerability management tools to track risk scores and remediation status
  • Evidence includes documented risk ratings, threat descriptions, and mitigation plans

Measurement & Maturity

  • Risk scores serve as key indicators for prioritization but do not measure control effectiveness directly
  • No formal maturity model; effectiveness depends on consistent application and integration with broader risk management
  • Common baseline involves using DREAD scores to prioritize high-risk vulnerabilities for remediation

Common Pitfalls

  • Over-reliance on subjective scoring leading to inconsistent risk ratings
  • Applying DREAD without integrating organizational context or asset criticality
  • Failure to update risk assessments as threat landscapes evolve, resulting in stale data

Integration & Mapping

  • Can complement frameworks like STRIDE for threat modeling or integrate with vulnerability management processes
  • Useful in governance, risk, and compliance (GRC) platforms to enhance risk prioritization
  • Limited direct mapping to formal control frameworks such as NIST or ISO but supports risk-based control selection

When Not to Use It

  • Not suitable as a standalone compliance framework or for organizations requiring regulatory-specific risk assessments
  • May be too subjective or granular for high-level executive reporting without additional context
  • Lightweight or automated risk scoring tools may be preferred in fast-paced or large-scale environments

Standards & References

  • Originally developed by Microsoft as part of threat modeling practices
  • Referenced in various security literature and threat modeling guides but lacks formal standardization
  • Companion materials include threat modeling methodologies such as STRIDE and risk assessment best practices
Tags: Cybersecurity Frameworks DREAD legacy models risk assessment Risk Prioritization Threat Modeling vulnerability management