Top Qs
Timeline
Chat
Perspective
DREAD (risk assessment model)
Computer security threat assessment model From Wikipedia, the free encyclopedia
Remove ads
DREAD (Damage, Reproducibility, Exploitability, Affected users, Discoverability) is a risk assessment and threat modeling system for computer security threats. When a given threat is assessed using DREAD, each category is given a rating from 1 to 10, and the sum of all ratings is taken to assess the overall risk.[1] It was formerly used at Microsoft before being discontinued for its inconsistency and subjectivity.[2][3] It has also been criticised for promoting security through obscurity through the discoverability element. Some organizations have moved to a DREAD-D "DREAD minus D" scale, which omits Discoverability.[4][5]
Remove ads
See also
References
External links
Wikiwand - on
Seamless Wikipedia browsing. On steroids.
Remove ads