By using database security metrics to evaluate how risky the current database environment is and visually displaying the metric results on graphs, database security visualization and assessment method assists the administrators in holding a panoramic view of security over the database system as well as the detailed activity of each DBMS in the system. The present trend shows that it is obviously a new potential branch and this paper will introduce an extensible framework to build flexible database security measuring systems. The proposed framework allows metrics processing cores to be written in different programming languages and reside in various places of the system, the final result to be displayed on a variety of user-predefined reports and graphs, and it also provides a holistic view of accesses to the whole database systems.