(c) Rebecca Herold, LLC 2008                                                                                                                                  Email Rebecca Herold
My Services                                                                                                                                              
I have over 18 years of information security, privacy and compliance experience, 12 years of which I spent as a practitioner tackling
the challenges that still exist today.  I have helped many organizations throughout the world with a wide range of projects.  Some of
the common project engagements include:
  • High-level Privacy Impact Assessment (PIA)
  • Comprehensive PIA
  • Corporate Privacy Governance Plan
  • Corporate Information Protection Governance Plan
  • PII Identification and Inventory
  • Create or Update (to align with OECD Privacy Principles and data protection laws)  Privacy Policies
  • Create Procedures to Support Privacy Policies
  • Create or Update ((to align with ISO 27002 standards and data protection laws) Information Security Policies
  • Create Procedures to Support Information Security Policies
  • Business Partner Privacy and Security Program Review
  • Privacy Incident Response Plan
  • Privacy Program Maintenance Plan
  • Information Security Incident Response Plan
  • Information Security Program Maintenance Plan
  • Information Privacy and Security Awareness and Training Strategy
  • Information Privacy and Security Awareness and Training Content, Communications and Activities Development and/or
    Delivery
  • Vet Information Security and Privacy Products

I have also done many unique types of projects, and can do whatever your organization needs to make your information security,
privacy and compliance practice as effective as possible.
I am also happy to create a contract for a Privacy and/or Security Consulting Retainer to provide up to a pre-determined number of
hours of monthly consulting help for your organization on any topics you need help with at the time.
The following are some of the positions I have assisted over the years with information security, privacy and compliance projects,
challenges and incidents:
  • Executive Management – Corporate Secretary, CxOs, Board of Directors
  • Information Security - CISOs/CSOs, Directors, Managers
  • Privacy - CPOs, Directors, Managers
  • Risk – Chief Risk Officer, Risk Managers
  • Compliance – Chief Compliance Officer, Compliance Managers
  • Ethics – Ethics Officer
  • Legal - General Counsel, Attorneys
  • Audit – VP of Internal Audit, Audit Managers
  • Finance – Chief Financial Officer, Finance Managers
  • Marketing - Directors, Managers
  • Human Resources - VPs, Directors, Managers
  • IT – Chief Information Officer, Directors, Managers
  • Corporate Unit Heads - Loss Prevention, Quality, Physical Security and Safety
  • Business Unit Heads

Contact me to discuss your projects and challenges.