skip to content

Numeric Scoring Systems

Putting a number on a threat with DREAD's five averaged dimensions or a CVSS vector of base, threat and environmental metrics. Interviewers care most about what the number leaves out.

on this pageshow

explore

questions

11

What do the five letters in DREAD stand for, and how is a DREAD score produced?

level: juniorimportance: must knowfreq 48%

answer

  1. five ordinal ratings, one number
  2. starts with how bad the outcome is
  3. two of the five are impact dimensions
  4. the last one is about being found
  5. combine the five by averaging

basics

~20 s

DREAD rates a threat on five dimensions - Damage, Reproducibility, Exploitability, Affected users and Discoverability - each given a small ordinal rating in the room, then collapses them into one number, classically their arithmetic mean.

solid answer

~50 s

DREAD is a per-threat rating scheme with five dimensions: **Damage** (how bad the outcome is if it happens), **Reproducibility** (how reliably the attack works when repeated), **Exploitability** (how much skill, access or effort it takes to pull off), **Affected users** (how much of the population is hit) and **Discoverability** (how easily an attacker finds the flaw in the first place). Each dimension gets an ordinal rating from a small scale - the classic form is 1 to 10, a common lighter variant is 1 to 3 - and the classic aggregation is the arithmetic mean of the five, giving one number you sort the threat list by. Two of the dimensions (Damage, Affected users) are about impact; the other three are about how likely and how easy the attack is. Nothing in DREAD comes with externally published per-value criteria, so the digits are the room's judgment, not a measurement.

go deeper

for a junior

Be ready to expand all five letters cleanly and say that the classic score is the average of five ratings. Do not confuse Reproducibility of the attack with reproducibility of the scoring.

for a middle

Explain that two dimensions measure impact and three measure ease or likelihood, and that the ratings are ordinal judgments with no externally published criteria behind them.

for a senior

Show where the scheme fits in a real session: enumeration produces the list, DREAD only orders it, and the ninety seconds it takes per threat is the main thing it has going for it.

for a principal

An interviewer expects you to frame it as one instrument among several and to be clear about what an unanchored per-threat number can and cannot justify to a stakeholder.

## What DREAD is for Once you have enumerated threats against a design, you have a list that is too long for the sprint you actually have. Risk rating is the step that turns that list into an order. DREAD is one of the oldest and simplest instruments for doing that: it asks five questions about each threat, takes a small ordinal rating for each, and combines them into a single number you can sort by. It came out of Microsoft in the early 2000s and was commonly taught alongside STRIDE - STRIDE to find the threats, DREAD to rank them - and it was later dropped from that guidance, for reasons this leaf's other questions cover. ## The five dimensions - **D - Damage potential.** How bad is the outcome if this threat is realised? Total loss of the data, a single record leaked, a few minutes of degraded service. This is an impact dimension. - **R - Reproducibility.** How reliably does the attack work if the attacker tries it again? A deterministic request that works every time rates high; a race that needs precise timing and succeeds one attempt in fifty rates low. Note the trap: this is about the *attack* being repeatable, not about your *scores* being repeatable, which is a completely different property and the one DREAD is most criticised for lacking. - **E - Exploitability.** How much effort, skill, tooling or pre-existing access does the attacker need? An unauthenticated request from anywhere rates high; something that needs a foothold on the host plus reverse-engineering rates low. - **A - Affected users.** How much of the population is hit? One administrator, one tenant, or everybody. This is the second impact dimension, and it is the blast-radius question. - **D - Discoverability.** How easily does an attacker find the flaw at all? Visible in a URL parameter rates high; buried in an undocumented internal message format rates low. A useful way to hold them: two dimensions ask *how bad*, three ask *how likely and how easy*. ## Producing the number Each dimension gets a rating from a fixed small scale. The original form uses 1 to 10 per dimension and takes the arithmetic mean of the five, so a threat's DREAD score also lands between 1 and 10. A widely used lighter variant scores each dimension 1, 2 or 3 (low / medium / high) and reads the *sum* against bands rather than averaging. Either way, the output is one number per threat, and the working assumption is that sorting by that number gives you a defensible order of work. A worked example on a multi-tenant reporting service, where the attacker position is an ordinary authenticated tenant with a valid login. The threat is that changing an identifier in a request returns another tenant's report: | Dimension | Rating | Why | | --- | --- | --- | | Damage potential | 7 | another customer's business data is exposed | | Reproducibility | 10 | the same request works every time | | Exploitability | 9 | edit one number in a URL, no tooling needed | | Affected users | 8 | every tenant on the shared instance | | Discoverability | 8 | the identifier is visible in the address bar | Mean of the five: **8.4**. That 8.4 is a DREAD score. It took about ninety seconds to produce, which is genuinely the scheme's strength. ## What the number is and is not It is worth being precise about the vocabulary, because interviewers probe it. The *threat* is "a tenant reads another tenant's report". The *vulnerability* is the missing ownership check on the identifier. The *risk* is the rated consequence - which is what DREAD is trying to express. The *control* is the ownership check you add. DREAD rates the third of those; it does not find threats, and it does not tell you what to build. It is also not a standard in the sense that a published scoring specification is. There is no authoritative document that tells you what Damage 7 means as opposed to Damage 6, so two teams rating the same threat are not using the same instrument even though they are using the same acronym. Some teams write their own per-value criteria to fix exactly this, and that is a reasonable thing to do - but the scheme does not ship with them. ## Where it sits in an interview Recalling the five letters is a screening-level question and you should be able to expand them without hesitation, including which two are impact dimensions. The follow-up is almost always about the arithmetic - whether averaging five subjective ordinal guesses gives you a number worth sorting by - so do not present the mean as though it were a measurement.

  • Which DREAD dimensions describe impact, and which describe likelihood?
    Damage potential and Affected users describe impact - how bad the outcome is and how many people it reaches. Reproducibility, Exploitability and Discoverability describe how likely and how easy the attack is. Averaging all five into one number therefore blends two axes that most risk methods deliberately keep separate, which is one reason the composite is hard to interpret.
  • What scale do the dimensions use, and does the scale change what the score means?
    The classic form scores each dimension 1 to 10 and averages; a lighter variant scores each 1 to 3 and reads the sum against bands. The scale changes the granularity but not the underlying property: in both cases the ratings are ordinal judgments, so a 10 is not ten times a 1, and the arithmetic treats the gaps as if they were equal.
  • Where does DREAD sit relative to threat enumeration?
    It runs after enumeration. Something else - a structured category walk over the design, an attack tree, an abuse case - produces the list of threats; DREAD only rates threats that already exist on the list. It has no elicitation power of its own, so a team that uses DREAD alone will rank a short and probably incomplete list very confidently.

It is a five-question opinion poll about one threat, where the answers are averaged into a single grade - fast to run, and only as good as the people answering.

saying these in an interview costs you the question

  • Calling DREAD a threat-enumeration method rather than a rating scheme
  • Reading the R as reproducibility of the score instead of the attack
  • Presenting the averaged digit as a measurement rather than a judgment
  • Cannot say which two dimensions are about impact
  • Claiming DREAD has published per-value criteria for each rating

context

open as a page

What does the CVSS v3.1 vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N tell you about a flaw?

level: middleimportance: must knowfreq 68%

basics

~20 s

A CVSS v3.1 base vector: network-reachable with low complexity, needing no privileges and no user interaction, escaping its own security scope to fully compromise confidentiality and integrity in the component it reaches, with no availability impact.

open as a page

Two findings both score CVSS 7.5 — how do EPSS and a known-exploited list change your order?

level: middleimportance: must knowfreq 66%

basics

~20 s

They break the tie on likelihood, which severity never measured. A finding in the top EPSS percentile and on a confirmed-exploitation list is being attacked now; an identical 7.5 in neither is a hypothesis. Same impact, very different urgency.

open as a page

What does a CVSS base score deliberately leave out about your own deployment?

level: middleimportance: must knowfreq 72%

basics

~20 s

A CVSS base score rates the flaw itself under reasonable worst-case assumptions. It ignores where your instance actually sits, how much the affected asset matters to your business, what controls already stand in the way, and how likely exploitation is.

open as a page

Why is DREAD's Discoverability dimension criticised as security by obscurity?

level: middleimportance: should knowfreq 33%

basics

~10 s

Discoverability lowers a threat's score because the flaw is hard to find, crediting obscurity as if it were a control. The vulnerability is unchanged; only attacker knowledge is, and that can shift overnight.

open as a page

In CVSS v3.1, what does Scope:Changed mean and when is it justified?

level: seniorimportance: should knowfreq 50%

basics

~20 s

Scope:Changed in CVSS v3.1 means the exploit crosses out of the vulnerable component's own security authority and impacts resources governed by a different one — a hypervisor escape reaching co-tenant VMs, for example. It raises the score, never lowers it.

open as a page

Two threats both average 6 in DREAD, one of them scoring Damage 1 and Affected users 10 - why is that ranking untrustworthy?

level: seniorimportance: should knowfreq 40%

basics

~20 s

Averaging five ordinal guesses destroys a threat's shape: a trivial issue touching everyone lands on the same digit as a moderate-everywhere one. The ratings are also unanchored, so a later session produces different digits from identical facts.

open as a page

Your CVSS 9.8 sits on a jump-host-only admin console and a 6.5 on the payments session path — which is worse?

level: seniorimportance: should knowfreq 58%

basics

~20 s

Almost certainly the 6.5. Rescore both with environmental metrics: the admin console flaw needs an attacker already inside the private network, while the payments path has high confidentiality, integrity and availability requirements, which lifts its score.

open as a page

Is migrating from CVSS v3.1's three metric groups to v4.0's four worth it for your programme?

level: principalimportance: nice to knowfreq 33%

basics

~20 s

CVSS v4.0 splits scoring into Base, Threat, Environmental and Supplemental groups, drops Scope for explicit subsequent-system impact, and adds non-scoring context such as Safety and Automatable. Migrating pays where those distinctions change decisions, not as a bulk re-score.

open as a page

Is DREAD worth keeping for a thirty-minute threat model of an internal service?

level: principalimportance: nice to knowfreq 24%

basics

~20 s

Keep the five prompts, throw away the arithmetic. Asking about damage, repeatability, effort, blast radius and visibility structures a short discussion well; computing and publishing a mean gives a number nobody can reconstruct or defend later.

open as a page

When may a compensating control lower a finding's CVSS rating, and what does that number then depend on?

level: principalimportance: nice to knowfreq 34%

basics

~20 s

Only when the control provably blocks the attack path, and only through environmental metrics, leaving the base score untouched. The lowered number then depends on that control existing, so record it as a precondition with a rescore trigger.

open as a page