skip to content

Risk Rating and Prioritization

Turning an enumerated threat list into a ranked backlog: DREAD, CVSS, bug bars, and defending an accept-or-fix call. Finding threats is easy; choosing which to fix is the senior skill.

on this pageshow

explore

questions

30

What do the five letters in DREAD stand for, and how is a DREAD score produced?

level: juniorimportance: must knowfreq 48%

answer

  1. five ordinal ratings, one number
  2. starts with how bad the outcome is
  3. two of the five are impact dimensions
  4. the last one is about being found
  5. combine the five by averaging

basics

~20 s

DREAD rates a threat on five dimensions - Damage, Reproducibility, Exploitability, Affected users and Discoverability - each given a small ordinal rating in the room, then collapses them into one number, classically their arithmetic mean.

solid answer

~50 s

DREAD is a per-threat rating scheme with five dimensions: **Damage** (how bad the outcome is if it happens), **Reproducibility** (how reliably the attack works when repeated), **Exploitability** (how much skill, access or effort it takes to pull off), **Affected users** (how much of the population is hit) and **Discoverability** (how easily an attacker finds the flaw in the first place). Each dimension gets an ordinal rating from a small scale - the classic form is 1 to 10, a common lighter variant is 1 to 3 - and the classic aggregation is the arithmetic mean of the five, giving one number you sort the threat list by. Two of the dimensions (Damage, Affected users) are about impact; the other three are about how likely and how easy the attack is. Nothing in DREAD comes with externally published per-value criteria, so the digits are the room's judgment, not a measurement.

go deeper

for a junior

Be ready to expand all five letters cleanly and say that the classic score is the average of five ratings. Do not confuse Reproducibility of the attack with reproducibility of the scoring.

for a middle

Explain that two dimensions measure impact and three measure ease or likelihood, and that the ratings are ordinal judgments with no externally published criteria behind them.

for a senior

Show where the scheme fits in a real session: enumeration produces the list, DREAD only orders it, and the ninety seconds it takes per threat is the main thing it has going for it.

for a principal

An interviewer expects you to frame it as one instrument among several and to be clear about what an unanchored per-threat number can and cannot justify to a stakeholder.

## What DREAD is for Once you have enumerated threats against a design, you have a list that is too long for the sprint you actually have. Risk rating is the step that turns that list into an order. DREAD is one of the oldest and simplest instruments for doing that: it asks five questions about each threat, takes a small ordinal rating for each, and combines them into a single number you can sort by. It came out of Microsoft in the early 2000s and was commonly taught alongside STRIDE - STRIDE to find the threats, DREAD to rank them - and it was later dropped from that guidance, for reasons this leaf's other questions cover. ## The five dimensions - **D - Damage potential.** How bad is the outcome if this threat is realised? Total loss of the data, a single record leaked, a few minutes of degraded service. This is an impact dimension. - **R - Reproducibility.** How reliably does the attack work if the attacker tries it again? A deterministic request that works every time rates high; a race that needs precise timing and succeeds one attempt in fifty rates low. Note the trap: this is about the *attack* being repeatable, not about your *scores* being repeatable, which is a completely different property and the one DREAD is most criticised for lacking. - **E - Exploitability.** How much effort, skill, tooling or pre-existing access does the attacker need? An unauthenticated request from anywhere rates high; something that needs a foothold on the host plus reverse-engineering rates low. - **A - Affected users.** How much of the population is hit? One administrator, one tenant, or everybody. This is the second impact dimension, and it is the blast-radius question. - **D - Discoverability.** How easily does an attacker find the flaw at all? Visible in a URL parameter rates high; buried in an undocumented internal message format rates low. A useful way to hold them: two dimensions ask *how bad*, three ask *how likely and how easy*. ## Producing the number Each dimension gets a rating from a fixed small scale. The original form uses 1 to 10 per dimension and takes the arithmetic mean of the five, so a threat's DREAD score also lands between 1 and 10. A widely used lighter variant scores each dimension 1, 2 or 3 (low / medium / high) and reads the *sum* against bands rather than averaging. Either way, the output is one number per threat, and the working assumption is that sorting by that number gives you a defensible order of work. A worked example on a multi-tenant reporting service, where the attacker position is an ordinary authenticated tenant with a valid login. The threat is that changing an identifier in a request returns another tenant's report: | Dimension | Rating | Why | | --- | --- | --- | | Damage potential | 7 | another customer's business data is exposed | | Reproducibility | 10 | the same request works every time | | Exploitability | 9 | edit one number in a URL, no tooling needed | | Affected users | 8 | every tenant on the shared instance | | Discoverability | 8 | the identifier is visible in the address bar | Mean of the five: **8.4**. That 8.4 is a DREAD score. It took about ninety seconds to produce, which is genuinely the scheme's strength. ## What the number is and is not It is worth being precise about the vocabulary, because interviewers probe it. The *threat* is "a tenant reads another tenant's report". The *vulnerability* is the missing ownership check on the identifier. The *risk* is the rated consequence - which is what DREAD is trying to express. The *control* is the ownership check you add. DREAD rates the third of those; it does not find threats, and it does not tell you what to build. It is also not a standard in the sense that a published scoring specification is. There is no authoritative document that tells you what Damage 7 means as opposed to Damage 6, so two teams rating the same threat are not using the same instrument even though they are using the same acronym. Some teams write their own per-value criteria to fix exactly this, and that is a reasonable thing to do - but the scheme does not ship with them. ## Where it sits in an interview Recalling the five letters is a screening-level question and you should be able to expand them without hesitation, including which two are impact dimensions. The follow-up is almost always about the arithmetic - whether averaging five subjective ordinal guesses gives you a number worth sorting by - so do not present the mean as though it were a measurement.

  • Which DREAD dimensions describe impact, and which describe likelihood?
    Damage potential and Affected users describe impact - how bad the outcome is and how many people it reaches. Reproducibility, Exploitability and Discoverability describe how likely and how easy the attack is. Averaging all five into one number therefore blends two axes that most risk methods deliberately keep separate, which is one reason the composite is hard to interpret.
  • What scale do the dimensions use, and does the scale change what the score means?
    The classic form scores each dimension 1 to 10 and averages; a lighter variant scores each 1 to 3 and reads the sum against bands. The scale changes the granularity but not the underlying property: in both cases the ratings are ordinal judgments, so a 10 is not ten times a 1, and the arithmetic treats the gaps as if they were equal.
  • Where does DREAD sit relative to threat enumeration?
    It runs after enumeration. Something else - a structured category walk over the design, an attack tree, an abuse case - produces the list of threats; DREAD only rates threats that already exist on the list. It has no elicitation power of its own, so a team that uses DREAD alone will rank a short and probably incomplete list very confidently.

It is a five-question opinion poll about one threat, where the answers are averaged into a single grade - fast to run, and only as good as the people answering.

saying these in an interview costs you the question

  • Calling DREAD a threat-enumeration method rather than a rating scheme
  • Reading the R as reproducibility of the score instead of the attack
  • Presenting the averaged digit as a measurement rather than a judgment
  • Cannot say which two dimensions are about impact
  • Claiming DREAD has published per-value criteria for each rating

context

open as a page

Your threat model readout goes to a risk committee: why is a CVSS score a poor headline, and what replaces it?

level: middleimportance: must knowfreq 62%

basics

~20 s

A CVSS score describes technical severity, not what the business loses. Lead each threat with a scenario: who does what, to whose money or data, and what it costs. Use the score only to rank items against each other.

open as a page

What is a bug bar in an SDL, and what does it decide about a security finding?

level: middleimportance: must knowfreq 60%

basics

~20 s

A bug bar is a written table, agreed before any finding exists, that defines each severity band by the concrete kinds of flaw that belong in it, the deadline to fix each band, and which bands block shipping.

open as a page

What does the CVSS v3.1 vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N tell you about a flaw?

level: middleimportance: must knowfreq 68%

basics

~20 s

A CVSS v3.1 base vector: network-reachable with low complexity, needing no privileges and no user interaction, escaping its own security scope to fully compromise confidentiality and integrity in the component it reaches, with no availability impact.

open as a page

In a threat model, how do you rate the likelihood that a warehouse picker's handheld can post fraudulent stock write-offs?

level: middleimportance: must knowfreq 70%

basics

~20 s

Rate likelihood from what the abuse requires, not from how clever it is: who already holds the access, how much effort and skill it takes, and whether anyone would notice. Every picker already has the scanner, so likelihood is high.

open as a page

Why is multiplying likelihood and impact band numbers on a 5x5 risk matrix unsound?

level: middleimportance: must knowfreq 58%

basics

~20 s

Risk-matrix band numbers are ordinal ranks, not measured quantities: they say one band is worse than the next, not how much worse. Multiplying ranks yields a score with no consistent meaning, so the ordering it produces is arbitrary.

open as a page

Two findings both score CVSS 7.5 — how do EPSS and a known-exploited list change your order?

level: middleimportance: must knowfreq 66%

basics

~20 s

They break the tie on likelihood, which severity never measured. A finding in the top EPSS percentile and on a confirmed-exploitation list is being attacked now; an identical 7.5 in neither is a hypothesis. Same impact, very different urgency.

open as a page

What does a CVSS base score deliberately leave out about your own deployment?

level: middleimportance: must knowfreq 72%

basics

~20 s

A CVSS base score rates the flaw itself under reasonable worst-case assumptions. It ignores where your instance actually sits, how much the affected asset matters to your business, what controls already stand in the way, and how likely exploitation is.

open as a page

What are the four treatment options for a threat found in a design review?

level: middleimportance: must knowfreq 70%

basics

~20 s

Mitigate: add a control that cuts likelihood or impact. Avoid: redesign so the threat cannot exist. Transfer: move the financial consequence to another party by contract or insurance. Accept: knowingly carry the residual risk, with an owner and an expiry.

open as a page

What makes a documented risk acceptance still defensible six months later?

level: seniorimportance: must knowfreq 55%

basics

~20 s

A defensible acceptance names the accountable owner, states the residual risk as a concrete outcome, records the evidence and compensating controls behind the call, gives the reason it was taken, and carries a hard expiry that forces a fresh decision.

open as a page

Why is sorting a threat model's rated threats by score descending a poor fix order?

level: principalimportance: must knowfreq 66%

basics

~20 s

A severity score says how bad a threat is - not what the fix costs, how many other threats it clears, or what must be right before a fixed launch date. Sorting by score alone gives an indefensible order of work.

open as a page

Why is DREAD's Discoverability dimension criticised as security by obscurity?

level: middleimportance: should knowfreq 33%

basics

~10 s

Discoverability lowers a threat's score because the flaw is hard to find, crediting obscurity as if it were a control. The vulnerability is unchanged; only attacker knowledge is, and that can shift overnight.

open as a page

Why rate all threats from one design-time model in a single sitting rather than as each one surfaces?

level: middleimportance: should knowfreq 44%

basics

~20 s

Rating the whole set in one pass keeps every threat on the same scale. Rated piecemeal over weeks, the bar drifts: what the group called High early becomes Medium later, so the resulting order is not comparable.

open as a page

Defending a do-not-fix: every support agent can read any customer account and you propose logging over redesign - how do you make that case to a privacy officer?

level: seniorimportance: should knowfreq 50%

basics

~20 s

State the threat and the actor plainly, then be exact about what logging changes: it makes an unauthorised look detectable and attributable, not impossible. Price the redesign you decline, and let the privacy officer decide, with a review date.

open as a page

How do you assign a bug bar severity to a modeled threat that has no proof of concept?

level: seniorimportance: should knowfreq 44%

basics

~20 s

Band the threat on the worst credible consequence if it is real, using the bar's flaw-class rows. Absence of a working exploit is not evidence of low severity; genuine doubt about whether the flaw exists becomes a time-boxed verification task, not a downgrade.

open as a page

In CVSS v3.1, what does Scope:Changed mean and when is it justified?

level: seniorimportance: should knowfreq 50%

basics

~20 s

Scope:Changed in CVSS v3.1 means the exploit crosses out of the vulnerable component's own security authority and impacts resources governed by a different one — a hypervisor escape reaching co-tenant VMs, for example. It raises the score, never lowers it.

open as a page

Two threats both average 6 in DREAD, one of them scoring Damage 1 and Affected users 10 - why is that ranking untrustworthy?

level: seniorimportance: should knowfreq 40%

basics

~20 s

Averaging five ordinal guesses destroys a threat's shape: a trivial issue touching everyone lands on the same digit as a moderate-everywhere one. The ratings are also unanchored, so a later session produces different digits from identical facts.

open as a page

How do you set a modeled threat's impact rating without inflating every finding to critical?

level: seniorimportance: should knowfreq 56%

basics

~20 s

Rate the worst credible loss this one threat delivers, not the worst story you can tell. Name what is reached, cap it at what the attacker's position gives them, then translate that into business and regulatory harm.

open as a page

How do you anchor risk-matrix impact bands so two raters land on the same cell?

level: seniorimportance: should knowfreq 46%

basics

~20 s

Replace adjective labels like Major with concrete, observable outcomes in the product's own vocabulary — for a photo-sharing service, Impact 4 means any cross-account read of another user's private media. Write the anchors before the rating argument, then calibrate them on past threats.

open as a page

Your CVSS 9.8 sits on a jump-host-only admin console and a 6.5 on the payments session path — which is worse?

level: seniorimportance: should knowfreq 58%

basics

~20 s

Almost certainly the 6.5. Rescore both with environmental metrics: the admin console flaw needs an attacker already inside the private network, while the payments path has high confidentiality, integrity and availability requirements, which lifts its score.

open as a page

Three high threats, one sprint before a ticketing on-sale: how do you run that trade-off with the product VP?

level: principalimportance: should knowfreq 42%

basics

~20 s

Bring priced options, not a demand: for each threat, a full fix, a partial mitigation, detection only, or a temporary control for the event. Then state what the deferred one costs, over what window, and get it owned and dated.

open as a page

With one sprint of capacity, do you fix the likely-but-bounded threat or the remote-but-catastrophic one?

level: principalimportance: should knowfreq 40%

basics

~20 s

Reject the framing that one rating decides both. Ship the cheap fix for the likely bounded threat this sprint, and treat the catastrophic one as an architecture decision with a named owner, a date and a written acceptance.

open as a page

How do you judge whether a mitigation's cost is justified by the loss it prevents?

level: principalimportance: should knowfreq 42%

basics

~20 s

Compare the control's full cost — build, operation and the user friction it adds — against the measured loss it prevents over a stated window, and record the assumptions. Tail risks and legal floors are not settled by that comparison.

open as a page

How does OWASP Risk Rating break likelihood and impact into factors you can grade?

level: middleimportance: nice to knowfreq 38%

basics

~20 s

OWASP Risk Rating splits likelihood into four threat-agent factors and four vulnerability factors, and impact into four technical and four business factors. Each is scored 0 to 9 and averaged within its group, then read as low, medium or high.

open as a page

A mitigation ships for a modeled threat — what do you re-rate, and how does the fix queue change?

level: seniorimportance: nice to knowfreq 27%

basics

~20 s

Re-rate the whole cluster the control touches, not just the row it targeted, and rate the new threats the control itself introduces. A mitigation usually lowers likelihood while leaving impact intact, so bands move, new rows appear, and the queue re-sorts.

open as a page

As the owner of a bug bar, how do you keep fix deadlines and the ship gate credible under launch pressure?

level: principalimportance: nice to knowfreq 33%

basics

~20 s

Agree the bands, clocks and gate before any finding exists, keep the gating set small enough that a block is believable, route acceptance to an accountable business owner rather than the security engineer, and change the bar only in scheduled reviews, never mid-argument.

open as a page

Is migrating from CVSS v3.1's three metric groups to v4.0's four worth it for your programme?

level: principalimportance: nice to knowfreq 33%

basics

~20 s

CVSS v4.0 splits scoring into Base, Threat, Environmental and Supplemental groups, drops Scope for explicit subsequent-system impact, and adds non-scoring context such as Safety and Automatable. Migrating pays where those distinctions change decisions, not as a bulk re-score.

open as a page

Is DREAD worth keeping for a thirty-minute threat model of an internal service?

level: principalimportance: nice to knowfreq 24%

basics

~20 s

Keep the five prompts, throw away the arithmetic. Asking about damage, repeatability, effort, blast radius and visibility structures a short discussion well; computing and publishing a mean gives a number nobody can reconstruct or defend later.

open as a page

A mobile operator's risk matrix rates seventy percent of modeled threats amber — what do you change?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

A matrix that rates most threats alike has stopped discriminating, so it cannot sequence work. Diagnose why first — vague bands, raters avoiding the extremes, or a colour region drawn across too many cells — then re-cut the bands against the real portfolio.

open as a page

When may a compensating control lower a finding's CVSS rating, and what does that number then depend on?

level: principalimportance: nice to knowfreq 34%

basics

~20 s

Only when the control provably blocks the attack path, and only through environmental metrics, leaving the base score untouched. The lowered number then depends on that control existing, so record it as a precondition with a rescore trigger.

open as a page