-
FIND ALL YOUR CYBER SECURITY ANSWERS ON OUR WIKI PAGE
The Cert2Connect wiki for a clear overview of terminology and the many abbreviations in the cyber, cloud and software security landscape.
Microsoft DREAD
Microsoft DREAD
Microsoft DREAD is a framework for assessing the risks of software vulnerabilities. DREAD is an acronym for the five factors that are evaluated:
- Damage potential (Potentially harmful impact)
- Reproducibility
- Exploitability (Vulnerability to exploit)
- Affected users (Number of affected users)
- Discoverability
DREAD's goal is to provide a structured and consistent way to quantify and prioritize security risks. This allows developers and security teams to focus their resources on the most critical vulnerabilities and patch them before they are exploited.
Updated on 07 Aug, 2023