There is some move to consider safety and security together in engineered systems and as a result I have come across - again - various informal notions of risk. I thought it worth while to perform a quick (but incomplete) survey of current standards and to try to elucidate the components currently thought to go together to constitute risk. http://www.abnormaldistribution.org/2016/01/12/risk/

In a nutshell, the project-management idea of risk as the chance that things will go badly wrong is on the way out (it's been replaced in ISO/IEC Guide 73). That's something to applaud, in my view. But there are often things wrong with the probability/likelihood component of our favored notion, and visible suggestions it be generalised into something like a measure of uncertainty.

