Matthew Squair writes eloquently on this subject at his blog "Dark Matter". I found one of his papers, "Current theory and practice of risk safety management", to be a good primer to the subject.
Here's his idea of the theory of safety:
Put this in a risk management context, and you get something like this:
Squair offers several 'take away' conclusions and suggestions, but I like this one:
Bookmark this on Delicious