BDのセキュリティ体制は、米国証券取引委員会(SEC)公式のForm 10-K(https://www.sec.gov/Archives/edgar/data/10795/000001079525000099/bdx-20250930.htm)で確認できます。このSourceでは、サイバーセキュリティのリスク管理プログラムがNISTサイバーセキュリティフレームワーク2.0を指針としていること、ISO/IEC 27001:2022、医療機器向けUL 2900-1、FD&C法524B条に基づくFDAの市販前・市販後ガイダンス、HSCC Joint Security Plan 2.0に整合させていること、全社レベルでISO/IEC 27001:2022認証を保有すること、CIO配下のCISOと製品セキュリティ担当VPが置かれ、取締役会の監査委員会と品質・規制委員会が監督することが記載されています。具体的には「National Institute of Standards and Technology (“NIST”) Cybersecurity Framework 2.0」、「International Organization for Standardization (“ISO”)/International Electrotechnical Commission (IEC) 27001:2022」、「Underwriters Laboratories (“UL”) 2900-1 Cybersecurity Standard for Medical Devices」、「Section 524B of the Federal Food, Drug, and Cosmetic Act (FD&C Act)」、「Healthcare Sector Coordinating Council (HSCC) Joint Security Plan (JSP) 2.0」、「In 2022, BD achieved ISO/IEC 27001:2022 certification at the enterprise level」、「Chief Information Security Officer (“CISO”)」、「Vice President, Research and Development, Product Security」、「the Audit Committee and the Quality and Regulatory Committee (QRC)」、「mandatory quarterly cybersecurity awareness training」、「we are not aware of any risks from cybersecurity threats that have materially affected or are reasonably likely to materially affect BD」といった記載が確認できます。限界として、認証・準拠・体制の状況は更新されうるため、この内容は取得時点のものです。適用範囲がどこまでかは、このSourceだけでは確認できない場合があります。 これは統制の枠組みに関する開示であり、実際の運用成熟度や個別インシデントの有無を示すものではありません。Current Statusとして、2026年8月21日に当該Sourceを取得し、上記の内容を確認しました。Source種別としては、これは米国証券取引委員会(SEC)に対する届出・開示、または米国証券取引委員会(SEC)が保持する公的記録であり、企業自身の広報や第三者による評価とは性質が異なります。