PermissionsThe Enforce Encryption in Transit with Flexible Match for AWS S3 Buckets policy pack requires 2 permissions:s3:DeleteBucketPolicys3:PutBucketPolicy