Glossary
GLOSSARY Measurement fundamentals

Metric vs. Measure

Last updated 27 Jul 2026

A measure is a raw observation. A metric is something derived from one or more measures. The distinction gets treated as pedantry, and then a measurement programme spends a year discovering why it was not.

The three layers

A measure is what a system reports directly. An endpoint agent reports its version. A scanner reports a finding with a severity. An HR system reports a completion date. No arithmetic, no interpretation.

A metric is computed. Share of endpoints running a supported agent version. Median age of open critical findings. Training completion rate by department. Each requires a decision about population, timing and method.

See metric vs. measure. An indicator is a metric that has been given a target, a threshold and an owner, so that its value implies an action.

Different failure modes, different fixes

Because the failure modes are different, and so are the fixes.

If a measure is wrong, the source is wrong. A collector broke, a field got renamed, a system stopped reporting. You fix the pipe.

If a metric is wrong, the definition is wrong. The denominator excluded a subsidiary, the window was calendar month instead of rolling thirty days, the severity mapping changed. You fix the formula and then decide whether to restate history.

Programmes that store only the computed metric cannot tell these apart. When a number looks odd, there is nothing underneath it to check, so the investigation becomes an argument.

Keep the raw observations

Keep the raw observations. Compute metrics from them rather than from earlier computed values where you can, and record which measures each metric drew on.

That single habit is what makes it possible to recompute a metric under a corrected definition two years later, and to answer the question that always comes eventually: was last year’s figure produced the same way as this year’s?