Title Page
-
Conducted on
-
Prepared by
-
Location
-
The purpose of this document is to prepare you to complete the Sonic Cybersecurity Store Self Assessment
Best Practices for your drive-in!
Physical Security:
-
Make sure doors are closed and locked
-
Always check and verify the ID of non-employees who want to come inside
-
Your server cabinet should be locked, and the keys should be stored in the safe
-
Each employee should have their own ID or MagCard to ring up transactions or clock in
-
Passwords should not be written down or shared
-
Sensitive information such as employee data (i.e., Social Security Number, Date of Birth, etc) or sales data (i.e. credit card information) must be locked in safe box or file cabinet.
-
When sensitive information is no longer needed, it must be securely shredded
-
Always securely erase or destroy outdated or defective hard drives
-
Post the Cybersecurity sticker and Anti-Vishing magnet so they are easily visible
-
Use a DVR system and/or security cameras to watch critical areas of the drive-in, including building access, POS systems, and the stalls
-
Check credit card machines daily for signs of skimmers. Check all of them; those inside and outside, including stalls. Keep a simple log of all your checks. If you do not know what a skimmer is, refer to e-learning guide.
System Access:
-
Sonic personnel from HQ or contracted vendors are the only people who should remotely connect to store systems. These include HQ, SEI, and INFOR support personnel.
-
Only equipment approved by Sonic is allowed to be utilized in drive-ins. Do not add your own equipment.
-
On the back-office computer/server, no additional software may be added. Only Sonic-approved applications are permitted.
-
Vigilix and Bomgar are the approved tools for support teams to remote in to your system. Do not install other tools
Training:
-
All personnel need to complete the Cybersecurity E-Learning modules on Partnernet
-
New hires in the drive-in need to complete the Skimmer Awareness training on Partnernet
-
Drive-ins should provide additional security awareness training regularly once the new hire training is complete