Permissions
The AWS CIS v3.0.0 - Section 1 - Identity and Access Management policy pack requires 18 permissions:
ec2:AssociateIamInstanceProfileec2:DescribeIamInstanceProfileAssociationsec2:ReplaceIamInstanceProfileAssociationiam:CreatePolicyVersioniam:DeleteAccessKeyiam:DeleteGroupPolicyiam:DeleteLoginProfileiam:DeletePolicyVersioniam:DeleteRolePolicyiam:DeleteServerCertificateiam:DeleteUserPolicyiam:DetachUserPolicyiam:ListPolicyVersionsiam:PutGroupPolicyiam:PutRolePolicyiam:PutUserPolicyiam:UpdateAccessKeyiam:UpdateAccountPasswordPolicy