Permissions
The Azure CIS v2.0.0 - Section 6 - Networking policy pack requires 4 permissions:
microsoft.network/networksecuritygroups/readmicrosoft.network/networksecuritygroups/writemicrosoft.network/networkwatchers/deletemicrosoft.network/networkwatchers/flowlogs/write