A clear definition of what constitutes a security metric is not easily found. Security metrics are more frequently defined by how they are used, or by the characteristics or attributes that make them useful.
One practical definition states that “Metrics is a term used to denote a measure based on a reference and involves at least two points, the measure and the reference. Security in its most basic meaning is the protection from or absence of danger. Literally, security metrics should tell us about the state or degree of safety relative to a reference point and
what to do to avoid danger.” (Brotby, 2009)
When we talk about security metrics we are referring to objective measurements that tell us about our current level of safety and show us how to achieve our goals. One author artfully distilled it all down to this statement. “The primary goal of metrics is to quantify data to facilitate insight.” (Jaquith, 2007)

From:http://www.sans.org/