The organization needs to exercise care with property (e.g. confidential data, personal data, materials, components, tools, equipment, premises, IP) belonging to customers or external providers while it is under the organization’s control or being used by the organization. The organization should describe general rules for doing this.
If there is property provided by customers or external providers, that is being incorporated into own products / services, the organization needs to have a process for separately identifying, verifying and protecting the property.
When any external property is lost, damaged or otherwise found to be unsuitable for use, the organization shall report this to the customer or external provider and retain documented information on what has occurred.