What do the five letters in DREAD stand for, and how is a DREAD score produced?
answer
- five ordinal ratings, one number
- starts with how bad the outcome is
- two of the five are impact dimensions
- the last one is about being found
- combine the five by averaging
basics
~20 sDREAD rates a threat on five dimensions - Damage, Reproducibility, Exploitability, Affected users and Discoverability - each given a small ordinal rating in the room, then collapses them into one number, classically their arithmetic mean.
solid answer
~50 sDREAD is a per-threat rating scheme with five dimensions: **Damage** (how bad the outcome is if it happens), **Reproducibility** (how reliably the attack works when repeated), **Exploitability** (how much skill, access or effort it takes to pull off), **Affected users** (how much of the population is hit) and **Discoverability** (how easily an attacker finds the flaw in the first place). Each dimension gets an ordinal rating from a small scale - the classic form is 1 to 10, a common lighter variant is 1 to 3 - and the classic aggregation is the arithmetic mean of the five, giving one number you sort the threat list by. Two of the dimensions (Damage, Affected users) are about impact; the other three are about how likely and how easy the attack is. Nothing in DREAD comes with externally published per-value criteria, so the digits are the room's judgment, not a measurement.
go deeper
Be ready to expand all five letters cleanly and say that the classic score is the average of five ratings. Do not confuse Reproducibility of the attack with reproducibility of the scoring.
Explain that two dimensions measure impact and three measure ease or likelihood, and that the ratings are ordinal judgments with no externally published criteria behind them.
Show where the scheme fits in a real session: enumeration produces the list, DREAD only orders it, and the ninety seconds it takes per threat is the main thing it has going for it.
An interviewer expects you to frame it as one instrument among several and to be clear about what an unanchored per-threat number can and cannot justify to a stakeholder.
## What DREAD is for Once you have enumerated threats against a design, you have a list that is too long for the sprint you actually have. Risk rating is the step that turns that list into an order. DREAD is one of the oldest and simplest instruments for doing that: it asks five questions about each threat, takes a small ordinal rating for each, and combines them into a single number you can sort by. It came out of Microsoft in the early 2000s and was commonly taught alongside STRIDE - STRIDE to find the threats, DREAD to rank them - and it was later dropped from that guidance, for reasons this leaf's other questions cover. ## The five dimensions - **D - Damage potential.** How bad is the outcome if this threat is realised? Total loss of the data, a single record leaked, a few minutes of degraded service. This is an impact dimension. - **R - Reproducibility.** How reliably does the attack work if the attacker tries it again? A deterministic request that works every time rates high; a race that needs precise timing and succeeds one attempt in fifty rates low. Note the trap: this is about the *attack* being repeatable, not about your *scores* being repeatable, which is a completely different property and the one DREAD is most criticised for lacking. - **E - Exploitability.** How much effort, skill, tooling or pre-existing access does the attacker need? An unauthenticated request from anywhere rates high; something that needs a foothold on the host plus reverse-engineering rates low. - **A - Affected users.** How much of the population is hit? One administrator, one tenant, or everybody. This is the second impact dimension, and it is the blast-radius question. - **D - Discoverability.** How easily does an attacker find the flaw at all? Visible in a URL parameter rates high; buried in an undocumented internal message format rates low. A useful way to hold them: two dimensions ask *how bad*, three ask *how likely and how easy*. ## Producing the number Each dimension gets a rating from a fixed small scale. The original form uses 1 to 10 per dimension and takes the arithmetic mean of the five, so a threat's DREAD score also lands between 1 and 10. A widely used lighter variant scores each dimension 1, 2 or 3 (low / medium / high) and reads the *sum* against bands rather than averaging. Either way, the output is one number per threat, and the working assumption is that sorting by that number gives you a defensible order of work. A worked example on a multi-tenant reporting service, where the attacker position is an ordinary authenticated tenant with a valid login. The threat is that changing an identifier in a request returns another tenant's report: | Dimension | Rating | Why | | --- | --- | --- | | Damage potential | 7 | another customer's business data is exposed | | Reproducibility | 10 | the same request works every time | | Exploitability | 9 | edit one number in a URL, no tooling needed | | Affected users | 8 | every tenant on the shared instance | | Discoverability | 8 | the identifier is visible in the address bar | Mean of the five: **8.4**. That 8.4 is a DREAD score. It took about ninety seconds to produce, which is genuinely the scheme's strength. ## What the number is and is not It is worth being precise about the vocabulary, because interviewers probe it. The *threat* is "a tenant reads another tenant's report". The *vulnerability* is the missing ownership check on the identifier. The *risk* is the rated consequence - which is what DREAD is trying to express. The *control* is the ownership check you add. DREAD rates the third of those; it does not find threats, and it does not tell you what to build. It is also not a standard in the sense that a published scoring specification is. There is no authoritative document that tells you what Damage 7 means as opposed to Damage 6, so two teams rating the same threat are not using the same instrument even though they are using the same acronym. Some teams write their own per-value criteria to fix exactly this, and that is a reasonable thing to do - but the scheme does not ship with them. ## Where it sits in an interview Recalling the five letters is a screening-level question and you should be able to expand them without hesitation, including which two are impact dimensions. The follow-up is almost always about the arithmetic - whether averaging five subjective ordinal guesses gives you a number worth sorting by - so do not present the mean as though it were a measurement.
- Which DREAD dimensions describe impact, and which describe likelihood?Damage potential and Affected users describe impact - how bad the outcome is and how many people it reaches. Reproducibility, Exploitability and Discoverability describe how likely and how easy the attack is. Averaging all five into one number therefore blends two axes that most risk methods deliberately keep separate, which is one reason the composite is hard to interpret.
- What scale do the dimensions use, and does the scale change what the score means?The classic form scores each dimension 1 to 10 and averages; a lighter variant scores each 1 to 3 and reads the sum against bands. The scale changes the granularity but not the underlying property: in both cases the ratings are ordinal judgments, so a 10 is not ten times a 1, and the arithmetic treats the gaps as if they were equal.
- Where does DREAD sit relative to threat enumeration?It runs after enumeration. Something else - a structured category walk over the design, an attack tree, an abuse case - produces the list of threats; DREAD only rates threats that already exist on the list. It has no elicitation power of its own, so a team that uses DREAD alone will rank a short and probably incomplete list very confidently.
It is a five-question opinion poll about one threat, where the answers are averaged into a single grade - fast to run, and only as good as the people answering.
saying these in an interview costs you the question
- Calling DREAD a threat-enumeration method rather than a rating scheme
- Reading the R as reproducibility of the score instead of the attack
- Presenting the averaged digit as a measurement rather than a judgment
- Cannot say which two dimensions are about impact
- Claiming DREAD has published per-value criteria for each rating