Technical Concepts
Resource identity and fingerprinting
How resources are identified for action, and how the same identity is reduced to a fingerprint so a stored snapshot names nothing.
Two different needs
For action, a resource must be named exactly, so you can open it. For comparison, only identity across two assessments is needed, and a name would be a stored customer identifier.
In the Evidence Register
Full identifiers, unmasked, in the register that is available on request. You own the account and cannot act on a masked identifier. The board pack shortens them instead, because the pack is the document that circulates.
In the snapshot
Fingerprints. Resource identity is carried as a derived value, and the account identifier is fingerprinted too. The snapshot therefore names no resource and no account, which is what makes retaining it for 90 days defensible when the raw evidence expires in one.
What is parsed from an identifier
The region and the service, and whether the control governs the account as a whole. Those feed reach and materiality.
Truncation
A bounded number of identifiers is tracked per control, and the register states explicitly whether the list is complete.
What it does not mean
A fingerprint is not reversible into a resource name, and the snapshot is never delivered to anyone.
