DREAD
Damage, Reproducibility, Exploitability, Affected Users, Discoverability
DREAD is a risk rating model that scores threats on five dimensions to produce a quantitative risk value. Each dimension receives a score from 1 to 10, and the average determines overall threat severity.
Cómo se usa en ciberseguridad
Security architects and penetration testers use DREAD scores to prioritize which vulnerabilities to fix first after threat modeling sessions. The model pairs well with STRIDE since STRIDE identifies threats and DREAD ranks their severity. Some organizations have replaced DREAD with CVSS, but it remains popular for its simplicity in threat modeling workshops.
Término relacionado en el glosario: dread
Las definiciones son explicaciones originales escritas con fines de desarrollo profesional. Para definiciones técnicas autorizadas, consulta NIST, ISO o el organismo de normalización correspondiente.