Clause 5.5 of ISO/TS 22317:2021 — Determining the Prioritized Activities
Introduction
Once top management has determined which products and services are most critical (Clause 5.4), the next step is to identify and prioritize the activities that enable their delivery.
Clause 5.5 of ISO/TS 22317:2021 ensures that an organization translates strategic priorities into operational recovery requirements — defining which activities must resume first, at what capacity, and within what timeframe after a disruption.
This clause is the operational core of the Business Impact Analysis (BIA) process — where management decisions evolve into tangible recovery objectives such as RTOs (Recovery Time Objectives) and MTPDs (Maximum Tolerable Periods of Disruption).
5.5 — Determining the Prioritized Activities
Clause 5.5 comprises six sub-clauses that guide the organization through a structured approach:
- Overview
- Inputs
- Identify Activities
- Set RTO for the Activities
- Define the Prioritized Activities
- Results
Each stage moves from broad prioritization to precise recovery determination.
5.5.1 — Overview
The focus here is on understanding how products and services, business processes, and activities interconnect.
· A product or service is the outcome delivered to a customer or stakeholder.
· A process is the chain of linked activities required to produce that outcome.
· An activity is an operational task or function performed by people, systems, or suppliers.
A product or service's criticality directly influences the criticality of its supporting activities. Therefore, activity prioritization must mirror business priority but also account for internal dependencies and sequencing.
Example:
If “Customer Support†is a critical service, then the “Call Handling,†“Ticket Escalation,†and “System Logging†activities inherit corresponding recovery priorities.
5.5.2 — Inputs
Accurate prioritization depends on comprehensive input data.
Clause 5.5.2 lists five essential sources of information:
|
Input |
Description |
|
BIA Scope |
Clarifies which functions and business units are included. |
|
Impact Types and Criteria |
Derived from Clause 5.3 — ensures standardized assessment. |
|
Product and Service Priorities |
Established under Clause 5.4 — drives downstream activity ranking. |
|
Known Dependencies |
Internal/external links, including IT, suppliers, or shared resources. |
|
Legal, Regulatory & Contractual Requirements |
Obligations influencing recovery timing or performance. |
5.5.3 — Identify Activities
Activity owners must list all discrete operational activities required to deliver each prioritized product or service.
Each activity should have:
- A clear description and purpose
- Identified outputs and recipients
- Supporting systems, facilities, and people
- Interdependencies (upstream / downstream)
This inventory forms the Activity Register — a critical dataset for assigning recovery objectives.
Crest Advisory Africa recommends mapping activities within the P²ST² Framework (People, Processes, Systems, Technologies & Tools) to guarantee full coverage of dependencies.
5.5.4 — Set RTO for the Activities
This is the analytical heart of Clause 5.5.
Step 1 — Assess Impacts Over Time
Using the impact types, criteria, and timeframes defined earlier (Clause 5.3), each activity is evaluated to determine how disruption affects the organization as time progresses.
Step 2 — Determine MTPD
The Maximum Tolerable Period of Disruption (MTPD) represents the threshold beyond which the impact becomes unacceptable.
Example: If a 12-hour outage of the “Customer Query System†causes severe reputational and regulatory damage, the MTPD = 12 hours.
Step 3 — Set the RTO
The Recovery Time Objective (RTO) must be shorter than the MTPD and realistic within existing or planned recovery capabilities.
It defines how quickly the activity must be restored to a minimum acceptable level.
Step 4 — Define Minimum Acceptable Capacity
RTOs must be expressed alongside the minimum level of operation achievable within that timeframe (e.g., 50 % capacity, manual workaround).
Example Table:
|
Activity |
MTPD |
RTO |
Minimum Capacity |
Dependency |
|
Frontline Call Handling |
8 hrs |
2 hrs |
50 % of agents |
CRM, Telephony System |
|
Payroll Processing |
24 hrs |
8 hrs |
70 % accuracy |
HRMS, Finance Server |
|
Customer Reporting |
48 hrs |
12 hrs |
80 % data availability |
BI Tools, Database |
5.5.5 — Define the Prioritized Activities
After setting RTOs, the organization creates a ranked list of prioritized activities.
This list becomes the bridge between impact analysis and continuity strategy.
Activities are typically grouped into recovery tiers:
|
Tier |
Description |
Recovery Expectation |
|
Tier 1 (Critical) |
Must resume immediately to prevent severe impact |
Within ≤ 4 hours |
|
Tier 2 (High) |
Important for service continuity but not immediately fatal |
Within ≤ 24 hours |
|
Tier 3 (Medium) |
Supports longer-term recovery |
Within ≤ 3 days |
|
Tier 4 (Low) |
Can be deferred with limited consequence |
> 3 days |
Top management must review and sign off on this prioritization, ensuring alignment with business objectives and resource capability.
5.5.6 — Results
The results of this clause provide the essential building blocks for continuity strategy development and resource planning.
Key deliverables include:
|
Deliverable |
Description |
|
Approved Activity Register |
Comprehensive list of all critical and supporting activities. |
|
RTO and MTPD Matrix |
Quantified recovery expectations for each activity. |
|
Dependency Mapping |
Documentation of upstream / downstream relationships. |
|
Prioritized Activity List |
Ranked according to recovery urgency and capacity. |
|
Top Management Approval Record |
Evidence of governance and oversight. |
These outcomes enable continuity planners to design recovery strategies (Clause 5.6 and 5.7) that are proportionate to business needs.
Crest Advisory Africa Best Practice Insights
- Data Integrity Checks — Validate all RTOs through peer review sessions with activity owners to prevent unrealistic recovery targets.
- Dependency Visualization — Use ISOLTX's interactive dependency maps to display cascading impacts across systems and departments.
- Integration with Risk Registers — Link each prioritized activity to its associated risks and controls to strengthen assurance.
- Continuous Improvement — Review RTO/MTPD data annually or after any major change to context or process.
- Cross-functional Collaboration — Encourage joint sessions between Operations, IT, HR, and Finance to align interdependent RTOs.
Conclusion
Clause 5.5 of ISO/TS 22317:2021 transforms the BIA from an executive decision into an operational blueprint for resilience.
It identifies what must be done, how soon, and at what capacity to keep the organization within its tolerance for disruption.
When executed using Crest Advisory Africa's integrated methodologies — including the P²ST² Framework, ISOLTX BIA Module, and Combined Assurance Matrix — organizations gain a clear, data-driven hierarchy of priorities.
This clarity enables precise resource allocation, effective recovery planning, and measurable assurance that continuity objectives are not only compliant with ISO 22317 but also drive Performance and Certainty across the enterprise.