The Contractual Vendor Risk Assessment (CVRA) is a critical process that identifies and manages risks related to third-party vendors. This process helps protect the university by reviewing the vendor’s security, privacy, and legal practices before making any agreements. It ensures vendors meet York’s data security standards and helps identify potential risks so your department can make informed decisions and keep our data safe.
If a product will access, store, process, or transmit York data, you’ll need to follow the CVRA request process before moving forward.
View Completed Security Assessments:
Click on the link to access the list of completed security assessments.
