Measuring software security directly is generally considered very difficult. We have used the BSIMM framework to measure the various activities that software developers do that might contribute to better software security, including architecture.
https://bsimm.com
Conference Paper Hunting for Aardvarks: Can Software Security Be Measured?
Conference Paper Software Security Maturity in Public Organisations