Permissions
The AWS CIS v3.0.0 - Section 2 - Storage policy pack requires 16 permissions:
ec2:CreateSnapshotec2:DeleteVolumeec2:DetachVolumeec2:DisableEbsEncryptionByDefaultec2:EnableEbsEncryptionByDefaultec2:ModifyEbsDefaultKmsKeyIdec2:StopInstancesec2:TerminateInstanceselasticfilesystem:DeleteFileSystemelasticfilesystem:DeleteMountTargetrds:DeleteDBInstancerds:ModifyDBInstancerds:StopDBInstances3:DeleteBucketPolicys3:PutBucketPolicys3:PutBucketPublicAccessBlock