5.3 Dependency Mapping & Resource Requirements
Key Takeaways
- ISO 22301:2019 Clause 8.2.2c mandates identifying and documenting all interdependencies and supporting resources required to operate prioritized activities.
- Internal dependencies encompass upstream and downstream operational workflows, specialized workforce skills, facilities, physical infrastructure, and interconnected IT middleware.
- External dependencies span multi-tier supply chain vendors, cloud service providers (CSPs), public utilities (power, water, HVAC), logistics carriers, and financial market counterparties.
- Resource requirements are dynamic and must be quantified across discrete recovery time horizons (e.g., T+0 to T+4h, T+4 to T+24h, T+24 to T+72h, T+72+h) rather than assuming static steady-state needs.
- A standardized Resource Requirements Matrix categorizes needs across the 5 Core Resource Pillars: People, Facilities, Technology, Information/Data, and Third-Party Suppliers.
5.3 Dependency Mapping & Resource Requirements
Executive Summary: Prioritized activities do not operate in isolation. In modern interconnected organizations, every core business process relies on a complex web of internal workflows, specialized human competencies, physical facilities, digital infrastructure, and external third-party suppliers. Mandated by ISO 22301:2019 Clause 8.2.2c and detailed in ISO/TS 22317:2021 Section 7, dependency mapping and resource estimation identify the vital assets necessary to sustain prioritized activities at their Minimum Business Continuity Objective (MBCO). Failure to map these interdependencies is the leading cause of business continuity plan failure during real-world crises.
1. Normative Requirements: ISO 22301 Clause 8.2.2c & ISO/TS 22317
Clause 8.2.2c of ISO 22301:2019 explicitly requires the organization to "identify dependencies and supporting resources for prioritized activities, including suppliers, outsourced partners, and other relevant interested parties."
+-------------------------------------------------------------------------+
| THE 5 CORE RESOURCE PILLARS (ISO 22301) |
+-------------------------------------------------------------------------+
| |
| 1. PEOPLE 2. FACILITIES 3. TECHNOLOGY |
| • Headcount • Workplaces • Hardware / Laptops |
| • Critical Skills • Cleanrooms • Software / SaaS / APIs |
| • Succession • Command Centers • Network Bandwidth / VPN |
| |
| 4. INFORMATION / DATA 5. SUPPLIERS / PARTNERS |
| • Database Records • Critical Tier-1 Vendors |
| • Physical Archives • Cloud / IaaS Providers |
| • Cryptographic Keys • Utilities (Power, Water, HVAC) |
| |
+-------------------------------------------------------------------------+
Why Dependency Mapping is Critical
When a disaster strikes, an organization does not merely lose a business process; it loses access to specific resources. If the BIA fails to identify that a mission-critical billing process depends on a legacy authentication server managed by an external contractor, the continuity strategy will fail, regardless of how thoroughly the billing team documented their manual procedures.
2. Internal Dependency Mapping
Internal dependencies represent operational relationships, assets, and workflows contained within the boundaries of the organization.
┌────────────────────────────────────────────────────────────────────────────┐
│ INTERNAL DEPENDENCY TAXONOMY │
├─────────────────────────────┬──────────────────────────────────────────────┤
│ DEPENDENCY CATEGORY │ CORE COMPONENTS & AUDIT CHECKPOINTS │
├─────────────────────────────┼──────────────────────────────────────────────┤
│ 1. Upstream Business Inputs │ • Feeder data from preceding departments │
│ │ • Internal approvals & authorization handoffs│
├─────────────────────────────┼──────────────────────────────────────────────┤
│ 2. Downstream Receivers │ • Internal consumers of process outputs │
│ │ • Financial ledger journal postings │
├─────────────────────────────┼──────────────────────────────────────────────┤
│ 3. People & Key Competencies│ • Single Points of Failure (SPOF personnel) │
│ │ • Specialized certifications / licenses │
├─────────────────────────────┼──────────────────────────────────────────────┤
│ 4. Facilities & Environment │ • Specialized physical production lines │
│ │ • Secure vault storage / climate control │
├─────────────────────────────┼──────────────────────────────────────────────┤
│ 5. ICT & Digital Assets │ • Core ERP / CRM / Database engines │
│ │ • Active Directory, DNS, IAM, SSO gateways │
└─────────────────────────────┴──────────────────────────────────────────────┘
1. Upstream and Downstream Workflow Interlocks
- Upstream Dependencies: The inputs, data feeds, raw materials, or authorizations that a prioritized activity requires before it can begin execution. (e.g., Loan Underwriting cannot execute without the KYC Verification Team's completed identity check).
- Downstream Dependencies: The internal processes that rely on the prioritized activity's output to function. (e.g., Payroll Processing outputs the journal entries required by General Ledger Reconciliation).
2. People and Specialized Competencies
Mapping human resources involves identifying Single Points of Failure (SPOF)—individuals who possess unique, undocumented institutional knowledge or specialized legal authorities:
- Regulatory License Holders: Certified nuclear operators, registered customs brokers, authorized banking signers.
- Technical Specialists: Legacy mainframe engineers, proprietary algorithm developers.
- Minimum Staffing Ratios: The baseline headcount required to sustain MBCO throughput.
3. Facilities and Environmental Infrastructure
Beyond generic office desks, many prioritized activities require specialized physical environments:
- Temperature- and humidity-controlled cleanrooms for pharmaceutical formulation.
- Secure, sound-dampened trading floors equipped with specialized multi-line trading turrets.
- Dedicated Emergency Operations Centers (EOC) equipped with independent power and satellite communications.
4. Internal ICT Infrastructure & Hidden Middleware Dependencies
Implementers must map not only top-level software applications, but also the underlying hidden digital plumbing:
- Identity & Access Management (IAM): Active Directory, Okta, OAuth providers, Single Sign-On (SSO) gateways.
- Network Infrastructure: Internal DNS servers, core routing switches, VLAN segments, VPN concentrators.
- Database Middleware: Messaging queues (Kafka, RabbitMQ), API gateways, microservice orchestration meshes.
3. External Dependency & Supply Chain Mapping (ISO/TS 22318 Alignment)
Modern enterprises are heavily reliant on third parties. ISO/TS 22318:2021 (Guidelines for supply chain continuity management) provides technical guidance for mapping multi-tier external dependencies.
[ Enterprise Prioritized Activity ]
│
▼
[ Tier-1 Critical Supplier ] ──► (e.g., Cloud Hosting Provider / Main SaaS)
│
▼
[ Tier-2 Upstream Vendor ] ──► (e.g., Third-Party Subsea Cable / Data Center Power)
│
▼
[ Tier-N Commodity Source ] ──► (e.g., Regional Municipal Power Grid / Fuel Refinery)
1. Multi-Tier Supplier Mapping
- Tier-1 Suppliers: Direct contractual partners providing critical services (e.g., payment processor, primary cloud provider, third-party logistics carrier).
- Tier-2 / Nth-Tier Suppliers: Subcontractors upon whom the Tier-1 vendor depends. For example, if your Tier-1 SaaS provider hosts its application in a single public cloud region, an outage in that cloud provider disables your Tier-1 vendor.
2. Public and Municipal Infrastructure Utilities
Prioritized activities often fail due to utility disruptions rather than direct physical damage:
- Electrical Power: Primary grid feeds, secondary substations, uninterruptible power supplies (UPS), on-site diesel generators, fuel delivery contracts.
- Telecommunications: Dual diverse fiber entry paths into the building, cellular failover, satellite uplinks.
- HVAC (Heating, Ventilation, Air Conditioning): Server room cooling, cleanroom positive pressure filtration.
- Municipal Water & Sanitation: Facility cooling towers, industrial processing lines, workforce sanitation.
3. Financial Market Infrastructure & Counterparties
- Clearinghouses (DTCC, Euroclear), SWIFT interbank messaging network, central bank payment switches, merchant acquiring banks.
| External Dependency Category | Vulnerability / Failure Mode | Continuity Countermeasure (Clause 8.3) |
|---|---|---|
| Cloud Service Provider (CSP) | Region-wide availability zone collapse | Multi-region active-active deployment or hybrid failover |
| Critical Tier-1 SaaS Vendor | Vendor bankruptcy, major cyber outage | Escrow of source code & daily offline data backup |
| Electrical Power Grid | Regional blackout / transformer explosion | N+1 backup generators with 72-hour fuel storage & priority refuel contract |
| Telecommunications | Backhoe severs primary fiber conduit | Geographically diverse conduit entry points with cellular/satellite backup |
| Specialized Logistics Carrier | National freight strike, fuel shortage | Pre-contracted secondary carrier agreements with guaranteed SLAs |
4. Time-Phased Resource Quantification Across Recovery Horizons
A critical concept tested on the Lead Implementer exam is that resource requirements are not static. Immediately following a disaster ($T+0$), an organization requires minimal triage resources. As recovery progresses toward backlog catch-up ($T+24\text{h}$ to $T+72\text{h}$), resource requirements peak, potentially exceeding normal baseline levels.
┌────────────────────────────────────────────────────────────────────────────┐
│ FOUR RECOVERY TIME HORIZONS │
├──────────────────────┬─────────────────────────────┬───────────────────────┤
│ RECOVERY HORIZON │ OPERATIONAL OBJECTIVE │ RESOURCE PROFILE │
├──────────────────────┼─────────────────────────────┼───────────────────────┤
│ Phase 1: Immediate │ Life safety, incident │ • Incident Command │
│ (T+0 to T+4 Hours) │ triage, site containment │ • Core IT triage leads│
│ │ │ • Emergency comms │
├──────────────────────┼─────────────────────────────┼───────────────────────┤
│ Phase 2: Contingency │ Resumption of prioritized │ • MBCO skeleton staff │
│ (T+4 to T+24 Hours) │ activities at MBCO capacity │ • Secondary site seats│
│ │ │ • Core cloud failover │
├──────────────────────┼─────────────────────────────┼───────────────────────┤
│ Phase 3: Work Catchup│ Backlog clearance, WRT │ • Surge staffing (120%│
│ (T+24 to T+72 Hours) │ reconciliation, queue flush │ • Overtime / temp FTE │
│ │ │ • Extra bandwidth/PCs │
├──────────────────────┼─────────────────────────────┼───────────────────────┤
│ Phase 4: Normalcy │ Full operational capacity, │ • 100% Workforce │
│ (T+72+ Hours) │ primary site restoration │ • Standard facilities │
│ │ │ • Normal supply chain │
└──────────────────────┴─────────────────────────────┴───────────────────────┘
Quantifying Resources Across Time Horizons
-
Phase 1: Triage & Invocation ($T+0\text{ to }T+4\text{ hours}$):
- People: Incident Commander, Crisis Management Team (CMT), IT Disaster Recovery leads (5–10% of total headcount).
- Facilities: Primary Emergency Operations Center (EOC) or virtual incident bridge.
- Technology: Emergency mass notification system (ENS), satellite phones, mobile laptops.
-
Phase 2: Core Resumption at MBCO ($T+4\text{ to }T+24\text{ hours}$):
- People: Prioritized activity process operators (25–40% headcount).
- Facilities: Alternate recovery site seats, secure remote home-office connectivity.
- Technology: Restored core database, essential ERP modules, minimum 50 Mbps dedicated bandwidth.
-
Phase 3: Extended Operations & Work Recovery ($T+24\text{ to }T+72\text{ hours}$):
- People: Operational staff plus surge/overtime personnel to process transaction backlogs (70–110% headcount).
- Facilities: Expanded alternate office space, auxiliary meeting rooms.
- Technology: Full application suite, transaction queue processing engines, printers/scanners.
-
Phase 4: Return to Normalcy ($T+72+\text{ hours}$):
- People: 100% headcount restored.
- Facilities: Reoccupied primary facility or permanent alternate headquarters.
- Technology: Primary data center normalized, synchronous replication re-established.
5. The Comprehensive Resource Requirements Matrix (Artifact Breakdown)
The Resource Requirements Matrix is the definitive operational deliverable linking BIA analytical findings to downstream continuity strategy design (Clause 8.3).
+---------------------------------------------------------------------------------------------------------+
| RESOURCE REQUIREMENTS MATRIX TEMPLATE |
+---------------------------------------------------------------------------------------------------------+
| ACTIVITY ID: FIN-002 |
| ACTIVITY NAME: Wholesale Commercial Wire Transfers & Treasury Clearing |
| BUSINESS UNIT: Corporate Treasury & Settlement |
| MTPD: 8 Hours | RTO: 2 Hours | RPO: 0 Seconds (Synchronous) | MBCO: 50% Volume (Wholesale only) |
+-------------------+--------------------+--------------------+--------------------+----------------------+
| RESOURCE PILLAR | T+0 to T+4 Hours | T+4 to T+24 Hours | T+24 to T+72 Hours | T+72+ Hours (Normal) |
+-------------------+--------------------+--------------------+--------------------+----------------------+
| 1. PEOPLE | 2 Settlement Leads | 8 Wire Operators | 14 Operators (Surge| 12 Full Staff |
| (Headcount & | 1 Security Officer | (MBCO Capacity) | Backlog Clearance) | |
| Roles) | (Authorizer) | | | |
+-------------------+--------------------+--------------------+--------------------+----------------------+
| 2. FACILITIES | Virtual Emergency | Alternate Hot Site | Alternate Hot Site | Primary Headquarters |
| (Workspaces & | Bridge | (10 Dedicated Desk | (16 Dedicated Desks| (Corporate Floor 4) |
| Locations) | | Positions) | + Breakroom) | |
+-------------------+--------------------+--------------------+--------------------+----------------------+
| 3. TECHNOLOGY | Laptops with VPN & | 10 Secure Dual- | 16 Dual-Monitor PCs| 12 Standard Banking |
| (Hardware, SW, | Hardware Tokens | Monitor Terminals; | Full Core Banking | Terminals; Dedicated |
| Bandwidth) | | SWIFT Alliance Lite| SWIFT Gateway | SWIFT Network |
| | | 100 Mbps Bandwidth | 200 Mbps Bandwidth | 500 Mbps Fiber |
+-------------------+--------------------+--------------------+--------------------+----------------------+
| 4. DATA & INFO | Read-Only Balance | Real-Time Restored | Fully Synchronized | Live Primary |
| (Databases & | Snapshot | Ledger (RPO=0) | Transaction Ledger | Production DB |
| Records) | | | | |
+-------------------+--------------------+--------------------+--------------------+----------------------+
| 5. SUPPLIERS & | Telecom Carrier | SWIFT Network; | SWIFT Network; | SWIFT Network; |
| THIRD PARTIES | (Emergency DNS) | Central Bank RTGS; | Central Bank RTGS; | Central Bank RTGS; |
| | | Cloud IaaS Provider| Cloud IaaS; Diesel | All Counterparties |
| | | | Fuel Supplier | |
+-------------------+--------------------+--------------------+--------------------+----------------------+
6. Worked Implementation Scenario: MedixBio Pharmaceuticals
Implementation Context
MedixBio produces temperature-sensitive oncology biologics. The Lead Implementer is conducting a dependency analysis for Prioritized Activity BIO-01: Sterile Bioreactor Fermentation & Cold-Chain Storage ($\text{MTPD} = 12\text{ hours}$, $\text{RTO} = 4\text{ hours}$, $\text{MBCO} = 100%$ batch preservation).
┌────────────────────────────────────────────────────────┐
│ MedixBio: Sterile Bioreactor Fermentation (BIO-01) │
└───────────────────────────┬────────────────────────────┘
│
┌──────────────────────────────┬───────┴──────────────────────┬──────────────────────────────┐
▼ ▼ ▼ ▼
┌─────────────────┐ ┌─────────────────┐ ┌─────────────────┐ ┌─────────────────┐
│ PEOPLE │ │ FACILITIES │ │ TECHNOLOGY │ │ THIRD-PARTY │
│ • 2 Bio-Chemical│ │ • Cleanroom B-4 │ │ • SCADA Climate │ │ • Industrial Gas│
│ Engineers │ │ • Class 100 HEPA│ │ Control Engine│ (Liquid Nitrogen Supplier)│
│ • 1 QA Release │ │ • Backup Diesel │ │ • Active Direct-│ │ • Primary Power │
│ Officer (SPOF)│ │ Generator A-2 │ │ ory SCADA Auth│ Grid Utility │
└─────────────────┘ └─────────────────┘ └─────────────────┘ └─────────────────┘
Uncovering Hidden Dependencies
During the cross-functional BIA workshop, the team uncovers two catastrophic hidden dependencies:
- Hidden IT Dependency: The bioreactor SCADA climate control system relies on a central Active Directory server located at corporate headquarters 50 miles away for user authentication. If the corporate network fails, local engineers cannot log into the bioreactor to adjust temperature controls.
- Hidden Supply Chain Dependency: The cryogenic cooling system requires liquid nitrogen replenishment every 8 hours. The single-source supplier's contract specifies a standard delivery SLA of 24 hours—violating MedixBio's 12-hour MTPD.
Continuity Remediation Actions (Clause 8.3 Input)
- IT Fix: Deploy a localized, offline-cached authentication controller on the factory floor.
- Supply Chain Fix: Renegotiate the vendor contract to include an emergency 4-hour delivery SLA and install an on-site dual-tank liquid nitrogen reserve holding 72 hours of emergency coolant.
7. PECB Exam Warning Traps & Implementation Pitfalls
[!CAUTION] Critical Exam Traps for Section 5.3
- Trap: Ignoring Common-Mode Failures & Shared Resource Conflicts:
- When multiple departments conduct BIAs independently, they often claim the same shared resources (e.g., Department A requests 50 seats at the alternate site, Department B requests 40 seats, and Department C requests 30 seats at an alternate facility that only has 60 total seats). The Lead Implementer must aggregate and normalize resource demands across the enterprise.
- Trap: Overlooking IT Infrastructure Dependencies (IAM / Active Directory / DNS):
- Business process owners frequently list applications (e.g., "SAP ERP") but fail to identify foundational infrastructure services (DNS, DHCP, Active Directory, MFA tokens, database clustering). Without these core services, application recovery is impossible.
- Trap: Assuming Supplier SLAs Automatically Equal Supplier Continuity:
- A standard vendor service level agreement (SLA) promising 99.9% uptime is NOT a business continuity plan. In a major regional crisis, the vendor may invoke force majeure. ISO 22301 requires verifying third-party continuity arrangements and assessing multi-tier dependencies (ISO/TS 22318).
During a BIA dependency analysis, an organization discovers that three separate operational departments have each developed BCPs that rely on occupying 100% of the available seats at the company's single alternate recovery facility during a disaster. What type of vulnerability does this scenario illustrate?
An enterprise relies on a critical Tier-1 SaaS customer relationship management (CRM) platform. The SaaS vendor provides a contract guaranteeing 99.99% system availability. Under ISO 22301:2019 and ISO/TS 22318, why is this contractual uptime SLA alone insufficient to guarantee supply chain business continuity?
Why must resource requirements in an ISO 22301 BIA be modeled across discrete recovery time horizons (e.g., T+0 to T+4h, T+4 to T+24h, T+24 to T+72h) rather than as a single static resource total?