公開済みEvidenceをIdentity / Capability / Credibility / Use Case / Constraints・Current Statusの軸で機械的に集約したものです(新規の主張・推測は含みません)。
Identity
Becton, Dickinson and Company(BD)は米国ニュージャージー州フランクリンレイクスに本社を置く医療機器メーカーである。注射器・注射針、静脈カテーテル、PICC、採血管などの医療消耗品を中核とし、ニューヨーク証券取引所にティッカー「BDX」で上場している。検証待ちAbout BD
BDは2025年10月1日付で組織を5つのグローバル事業セグメント(Medical Essentials、Connected Care、BioPharma Systems、Interventional、Life Sciences)へ再編した。その後Life Sciencesセグメントが分離されたため、現在の報告セグメントは残る4区分となっている。検証待ちBecton Dickinson & Co - Form 10-Q(FY2026)
米国証券取引委員会(SEC)公式のForm 10-K(https://www.sec.gov/Archives/edgar/data/10795/000001079525000099/bdx-20250930.htm)は、BDのセキュリティ体制に関する公的記録である。同Sourceでは、サイバーセキュリティのリスク管理プログラムがNISTサイバーセキュリティフレームワーク2.0を指針としていること、ISO/IEC 27001:2022、医療機器向けUL 2900-1、FD&C法524B条に基づくFDAの市販前・市販後ガイダンス、HSCC Joint Security Plan 2.0に整合させていること、全社レベルでISO/IEC 27001:2022認証を保有すること、CIO配下のCISOと製品セキュリティ担当VPが置かれ、取締役会の監査委員会と品質・規制委員会が監督することが記載されています。具体的には「National Institute of Standards and Technology (“NIST”) Cybersecurity Framework 2.0」、「International Organization for Standardization (“ISO”)/International Electrotechnical Commission (IEC) 27001:2022」、「Underwriters Laboratories (“UL”) 2900-1 Cybersecurity Standard for Medical Devices」、「Section 524B of the Federal Food, Drug, and Cosmetic Act (FD&C Act)」、「Healthcare Sector Coordinating Council (HSCC) Joint Security Plan (JSP) 2.0」、「In 2022, BD achieved ISO/IEC 27001:2022 certification at the enterprise level」、「Chief Information Security Officer (“CISO”)」、「Vice President, Research and Development, Product Security」、「the Audit Committee and the Quality and Regulatory Committee (QRC)」、「mandatory quarterly cybersecurity awareness training」、「we are not aware of any risks from cybersecurity threats that have materially affected or are reasonably likely to materially affect BD」といった記載がある。ただし、認証・準拠・体制の状況は更新されうるため、この内容は取得時点のものです。適用範囲がどこまでかは、このSourceだけでは確認できない場合があります。 これは統制の枠組みに関する開示であり、実際の運用成熟度や個別インシデントの有無を示すものではありません。2026年8月21日に同Sourceを取得し、この内容を確認した。検証待ちBDのセキュリティ体制に関する公開情報