Top Qs
Timeline
Chat
Perspective

DREAD (risk assessment model)

Computer security threat assessment model From Wikipedia, the free encyclopedia

Remove ads

DREAD (Damage, Reproducibility, Exploitability, Affected users, Discoverability) is a risk assessment and threat modeling system for computer security threats. When a given threat is assessed using DREAD, each category is given a rating from 1 to 10, and the sum of all ratings is taken to assess the overall risk.[1] It was formerly used at Microsoft before being discontinued for its inconsistency and subjectivity.[2][3] It has also been criticised for promoting security through obscurity through the discoverability element. Some organizations have moved to a DREAD-D "DREAD minus D" scale, which omits Discoverability.[4][5]

Remove ads

See also

References

Loading related searches...

Wikiwand - on

Seamless Wikipedia browsing. On steroids.

Remove ads