Choice of security parameters for different combinations of data types that can be selected in Figure 4
| Data type options and combinations | Secret sharing parameters k/N and other protection settings |
|---|---|
| (DataType 1: Sensitive personal data, business secrets, security-classified data; DataType 2: time-critical data; DataType 3: Organizational critical data) | (k: threshold, N: no of servers) |
| DataType 1 | 4/5, two servers from private cloud and three from externals CSPs with data processing agreements, all servers located in the EEA; additional use of encryption |
| DataType 1 and DataType 2 | 4/5, two servers from private cloud and three from externals CSPs with data processing agreements, all servers located in the EEA and preferably (i.e. if available) with a low distance from the user’s location and high uptime guarantees; additional use of encryption |
| DataType 1 and DataType 3 | 5/7, three servers from private cloud and four from externals CSPs, all servers to be placed in the EEA but in different geographic areas and preferably with good incident management ratings; additional use of encryption |
| DataType 1 and DataType 2 and DataType 3 | 4/6, three servers from private cloud and three from externals CSPs, all servers to be placed in the EEA but in different geographic areas, however still in a low distance from the user’s location and preferably with good incident management ratings and high up-time guarantees; additional use of encryption |
| DataType 2 | 2/4, servers have a low distance from the user’s location and high up-time guarantees; fast caching can be realized by storing two chunks on local servers (If personal data: only CSPs with data processing agreements, all servers located in the EEA) |
| DataType 2 and DataType 3 | 2/3, servers from different geographic areas, preferably with good incident management ratings and high uptime guarantees (If personal data: only CSPs with data processing agreements, all servers located in the EEA) |
| DataType 3 | 3/5, servers to be placed in different geographic areas with good incident management ratings (If personal data: only CSPs with data processing agreements, all servers located in the EEA.) |
| No data type option selected | 2/4 (If personal data: 3/5, only CSPs with data processing agreements, all servers located in the EEA.) |
| Data type options and combinations | Secret sharing parameters k/N and other protection settings |
|---|---|
| ( | (k: threshold, N: no of servers) |
| DataType 1 | 4/5, two servers from private cloud and three from externals CSPs with data processing agreements, all servers located in the EEA; additional use of encryption |
| DataType 1 and DataType 2 | 4/5, two servers from private cloud and three from externals CSPs with data processing agreements, all servers located in the EEA and preferably (i.e. if available) with a low distance from the user’s location and high uptime guarantees; additional use of encryption |
| DataType 1 and DataType 3 | 5/7, three servers from private cloud and four from externals CSPs, all servers to be placed in the EEA but in different geographic areas and preferably with good incident management ratings; additional use of encryption |
| DataType 1 and DataType 2 and DataType 3 | 4/6, three servers from private cloud and three from externals CSPs, all servers to be placed in the EEA but in different geographic areas, however still in a low distance from the user’s location and preferably with good incident management ratings and high up-time guarantees; additional use of encryption |
| DataType 2 | 2/4, servers have a low distance from the user’s location and high up-time guarantees; fast caching can be realized by storing two chunks on local servers (If personal data: only CSPs with data processing agreements, all servers located in the EEA) |
| DataType 2 and DataType 3 | 2/3, servers from different geographic areas, preferably with good incident management ratings and high uptime guarantees (If personal data: only CSPs with data processing agreements, all servers located in the EEA) |
| DataType 3 | 3/5, servers to be placed in different geographic areas with good incident management ratings (If personal data: only CSPs with data processing agreements, all servers located in the EEA.) |
| No data type option selected | 2/4 (If personal data: 3/5, only CSPs with data processing agreements, all servers located in the EEA.) |