Clause 5.5 of ISO/TS 22317:2021 — Determining the Prioritized Activities

Introduction

Once top management has determined which products and services are most critical (Clause 5.4), the next step is to identify and prioritize the activities that enable their delivery.
Clause 5.5 of ISO/TS 22317:2021 ensures that an organization translates strategic priorities into operational recovery requirements — defining which activities must resume first, at what capacity, and within what timeframe after a disruption.

This clause is the operational core of the Business Impact Analysis (BIA) process — where management decisions evolve into tangible recovery objectives such as RTOs (Recovery Time Objectives) and MTPDs (Maximum Tolerable Periods of Disruption).

5.5 — Determining the Prioritized Activities

Clause 5.5 comprises six sub-clauses that guide the organization through a structured approach:

  1. Overview
  2. Inputs
  3. Identify Activities
  4. Set RTO for the Activities
  5. Define the Prioritized Activities
  6. Results

Each stage moves from broad prioritization to precise recovery determination.

5.5.1 — Overview

The focus here is on understanding how products and services, business processes, and activities interconnect.

· A product or service is the outcome delivered to a customer or stakeholder.

· A process is the chain of linked activities required to produce that outcome.

· An activity is an operational task or function performed by people, systems, or suppliers.

A product or service's criticality directly influences the criticality of its supporting activities. Therefore, activity prioritization must mirror business priority but also account for internal dependencies and sequencing.

Example:
If “Customer Support” is a critical service, then the “Call Handling,” “Ticket Escalation,” and “System Logging” activities inherit corresponding recovery priorities.

5.5.2 — Inputs

Accurate prioritization depends on comprehensive input data.
Clause 5.5.2 lists five essential sources of information:

Input

Description

BIA Scope

Clarifies which functions and business units are included.

Impact Types and Criteria

Derived from Clause 5.3 — ensures standardized assessment.

Product and Service Priorities

Established under Clause 5.4 — drives downstream activity ranking.

Known Dependencies

Internal/external links, including IT, suppliers, or shared resources.

Legal, Regulatory & Contractual Requirements

Obligations influencing recovery timing or performance.

5.5.3 — Identify Activities

Activity owners must list all discrete operational activities required to deliver each prioritized product or service.

Each activity should have:

  • A clear description and purpose
  • Identified outputs and recipients
  • Supporting systems, facilities, and people
  • Interdependencies (upstream / downstream)

This inventory forms the Activity Register — a critical dataset for assigning recovery objectives.

Crest Advisory Africa recommends mapping activities within the P²ST² Framework (People, Processes, Systems, Technologies & Tools) to guarantee full coverage of dependencies.

5.5.4 — Set RTO for the Activities

This is the analytical heart of Clause 5.5.

Step 1 — Assess Impacts Over Time

Using the impact types, criteria, and timeframes defined earlier (Clause 5.3), each activity is evaluated to determine how disruption affects the organization as time progresses.

Step 2 — Determine MTPD

The Maximum Tolerable Period of Disruption (MTPD) represents the threshold beyond which the impact becomes unacceptable.
Example: If a 12-hour outage of the “Customer Query System” causes severe reputational and regulatory damage, the MTPD = 12 hours.

Step 3 — Set the RTO

The Recovery Time Objective (RTO) must be shorter than the MTPD and realistic within existing or planned recovery capabilities.

It defines how quickly the activity must be restored to a minimum acceptable level.

Step 4 — Define Minimum Acceptable Capacity

RTOs must be expressed alongside the minimum level of operation achievable within that timeframe (e.g., 50 % capacity, manual workaround).

Example Table:

Activity

MTPD

RTO

Minimum Capacity

Dependency

Frontline Call Handling

8 hrs

2 hrs

50 % of agents

CRM, Telephony System

Payroll Processing

24 hrs

8 hrs

70 % accuracy

HRMS, Finance Server

Customer Reporting

48 hrs

12 hrs

80 % data availability

BI Tools, Database

5.5.5 — Define the Prioritized Activities

After setting RTOs, the organization creates a ranked list of prioritized activities.
This list becomes the bridge between impact analysis and continuity strategy.

Activities are typically grouped into recovery tiers:

Tier

Description

Recovery Expectation

Tier 1 (Critical)

Must resume immediately to prevent severe impact

Within ≤ 4 hours

Tier 2 (High)

Important for service continuity but not immediately fatal

Within ≤ 24 hours

Tier 3 (Medium)

Supports longer-term recovery

Within ≤ 3 days

Tier 4 (Low)

Can be deferred with limited consequence

> 3 days

Top management must review and sign off on this prioritization, ensuring alignment with business objectives and resource capability.

5.5.6 — Results

The results of this clause provide the essential building blocks for continuity strategy development and resource planning.
Key deliverables include:

Deliverable

Description

Approved Activity Register

Comprehensive list of all critical and supporting activities.

RTO and MTPD Matrix

Quantified recovery expectations for each activity.

Dependency Mapping

Documentation of upstream / downstream relationships.

Prioritized Activity List

Ranked according to recovery urgency and capacity.

Top Management Approval Record

Evidence of governance and oversight.

These outcomes enable continuity planners to design recovery strategies (Clause 5.6 and 5.7) that are proportionate to business needs.

Crest Advisory Africa Best Practice Insights

  1. Data Integrity Checks — Validate all RTOs through peer review sessions with activity owners to prevent unrealistic recovery targets.
  2. Dependency Visualization — Use ISOLTX's interactive dependency maps to display cascading impacts across systems and departments.
  3. Integration with Risk Registers — Link each prioritized activity to its associated risks and controls to strengthen assurance.
  4. Continuous Improvement — Review RTO/MTPD data annually or after any major change to context or process.
  5. Cross-functional Collaboration — Encourage joint sessions between Operations, IT, HR, and Finance to align interdependent RTOs.

Conclusion

Clause 5.5 of ISO/TS 22317:2021 transforms the BIA from an executive decision into an operational blueprint for resilience.

It identifies what must be done, how soon, and at what capacity to keep the organization within its tolerance for disruption.

When executed using Crest Advisory Africa's integrated methodologies — including the P²ST² Framework, ISOLTX BIA Module, and Combined Assurance Matrix — organizations gain a clear, data-driven hierarchy of priorities.

This clarity enables precise resource allocation, effective recovery planning, and measurable assurance that continuity objectives are not only compliant with ISO 22317 but also drive Performance and Certainty across the enterprise.