PermissionsThe Enforce Encryption at Rest Is Enabled for AWS S3 Buckets policy pack requires 5 permissions:s3:DeleteBucketEncryptions3:DeleteBucketPolicys3:PutBucketEncryptions3:PutBucketPolicys3:PutEncryptionConfiguration