Clause 5.6 of ISO/TS 22317:2021 — Identifying Resources and Dependencies for Recovery
Introduction
Once an organization has defined and prioritized its critical activities (Clause 5.5), it must determine what those activities need to function and recover effectively after disruption.
Clause 5.6 of ISO/TS 22317:2021 requires organizations to identify the resources and dependencies essential for restoring prioritized activities within their Recovery Time Objectives (RTOs).
This stage is where business continuity becomes practical — bridging analytical insight with operational reality. It ensures that recovery strategies, when developed, are grounded in verified resource requirements, not assumptions.
5.6 — Identify Resources and Other Dependencies
Clause 5.6 comprises two key sub-clauses:
5.6.1 Identify Resource and Other Dependency Requirements
5.6.2 Resource Requirements
Together, they establish the process of mapping everything an activity depends on to achieve its minimum acceptable capacity within defined RTOs.
5.6.1 — Identify Resource and Other Dependency Requirements
Purpose
This step involves gathering detailed information on the people, systems, facilities, data, and suppliers required to support each prioritized activity.
It ensures that continuity planners understand both the type and timing of resources needed to maintain or restore operations.
Core Resource Categories
ISO 22317 outlines eight major resource categories to be assessed:
|
Resource Type |
Description |
Example Considerations |
|
People |
Required skills, roles, and headcount |
How many employees or contractors are needed to perform minimum service? |
|
Information & Data |
Records, databases, and critical knowledge |
Which datasets are essential to resume operations? Where are they stored? |
|
Facilities & Infrastructure |
Buildings, offices, utilities, workspaces |
What physical locations are needed and what are their alternate sites? |
|
Equipment & Materials |
Machinery, tools, consumables |
Are there spares or alternative suppliers available? |
|
ICT Systems & Applications |
Core software, hardware, and communications |
Which systems must be online within the RTO? What is their RPO? |
|
Transportation & Logistics |
Vehicles, supply lines, delivery routes |
How will resources or staff reach alternate sites? |
|
Finance |
Access to funds, banking, payroll continuity |
Are emergency payment processes in place? |
|
Partners & Suppliers |
External service providers and dependencies |
Which contracts include recovery clauses or SLAs? |
These resources form the operational backbone of the Business Continuity Management System (BCMS).
Dependency Mapping
Dependencies exist both internally (between departments or systems) and externally (through suppliers, utilities, or regulators).
Each must be catalogued to reveal single points of failure or recovery bottlenecks.
Crest Advisory Africa applies the P²ST² Framework (People, Processes, Systems, Technologies, Tools) to guarantee full coverage of dependencies during this phase. This structured approach avoids blind spots by ensuring every layer of operational reliance is captured and validated.
5.6.2 — Resource Requirements
Purpose
This step defines the quantity, timing, and characteristics of each resource needed for recovery.
It also identifies any constraints that could affect availability during a disruption.
Resource Analysis Criteria
Each identified resource should be assessed against the following:
Quantity Required Over Time
Determine how much of each resource is needed at various recovery stages:
· Initial Response Phase: minimal resources to stabilize operations.
· Ramp-Up Phase: additional resources to reach acceptable service levels.
· Return to Business-as-Usual: full restoration.
Availability Timeframe
When must the resource be available to meet the RTO?
Example: Key staff within 2 hours; ERP system within 4 hours; facility access within 8 hours.
Critical Characteristics
Define the essential attributes of the resource:
· For staff: required qualifications or clearances.
· For IT systems: configuration, security, and performance specifications.
· For facilities: power, connectivity, safety features.
Recovery Point Objective (RPO)
Identify data tolerance thresholds — the maximum tolerable data loss for each system or information asset.
RPO ensures alignment between data backup strategies and operational priorities.
Legal & Regulatory Constraints
Highlight any compliance or contractual requirements that influence resource usage, such as data-sovereignty laws, labour legislation, or service-level penalties.
Inter-Resource Dependencies
Map relationships among resources — for example, a call-centre's telephony platform depends on network connectivity and power supply.
Single Points of Failure
Identify any resource without redundancy. Document and escalate these risks for mitigation planning.
Illustrative Resource Table
|
Activity |
Resource |
Minimum Quantity |
Required Within |
Dependency |
RPO |
Notes |
|
Frontline Call Handling |
Trained Agents |
10 |
2 hours |
Telephony System |
N/A |
Cross-trained backup staff available |
|
CRM System |
Application Server |
1 |
1 hour |
Data Centre Power |
15 min |
Real-time replication required |
|
Customer Data |
Database |
N/A |
1 hour |
Cloud Backup Service |
15 min |
Encrypted storage mandatory |
|
Facilities |
Office / BCP Site |
1 |
4 hours |
Utilities, Access Control |
N/A |
Hot-site capacity confirmed |
Integration with the Business Continuity Strategy
The information captured in Clause 5.6 directly feeds into:
Continuity Strategy Selection under ISO/TS 22331.
Resource and Capability Plans for each recovery site.
Supplier and Outsourcing Reviews (aligning RTO/RPO expectations with SLAs).
Incident Response Plans and Training & Awareness Programs.
By quantifying what each prioritized activity truly needs to recover, organizations can develop cost-effective, evidence-based resilience strategies rather than speculative plans.
Crest Advisory Africa Best-Practice Insights
· Digital Resource Inventory:
Use platforms such as the ISOLTX BCMS Module to maintain a live, auditable repository of all critical resources and dependencies.
· Cross-Validation Workshops:
Conduct verification sessions with IT, HR, Finance, and Operations to confirm accuracy of RTO/RPO dependencies.
· Dependency Visualization:
Employ tools like the ISOLTX Dependency Map to graphically display interconnections and identify cascade-failure risks.
· Combined Assurance Alignment:
Correlate resource dependencies with the organization's Risk Register, Audit Findings, and Compliance Controls to ensure assurance coverage.
· Continuous Monitoring:
Review and update resource data quarterly or following major structural or technological changes to maintain BCMS accuracy.
Outputs of Clause 5.6
|
Deliverable |
Description |
|
Resource Inventory |
Comprehensive list of all resources linked to prioritized activities. |
|
Dependency Matrix |
Visualization of internal and external interdependencies. |
|
RTO/RPO Alignment Table |
Confirms timing and data-loss tolerances per resource. |
|
Single Points of Failure Register |
Identifies areas requiring redundancy or investment. |
|
Updated BCMS Records |
Integration of all information into the BCMS knowledge base. |
Conclusion
Clause 5.6 of ISO/TS 22317:2021 transforms the Business Impact Analysis from a theoretical prioritization model into a fully contextual, resource-driven resilience framework.
By systematically identifying and validating resource and dependency requirements, organizations gain the operational intelligence necessary to develop realistic, cost-effective continuity strategies.
At Crest Advisory Africa, we view Clause 5.6 as the link between risk, continuity, and capability — ensuring that every recovery objective is supported by tangible resources and aligned with corporate governance expectations.
When executed through our P²ST² Methodology and powered by the ISOLTX GRC Platform, organizations achieve true Performance and Certainty across all layers of their Business Continuity Management System.