Permissions
The Azure CIS v2.0.0 - Section 8 - Key Vault policy pack requires 4 permissions:
microsoft.keyvault/vaults/delete
microsoft.keyvault/vaults/keys/update/action
microsoft.keyvault/vaults/secrets/update/action
microsoft.keyvault/vaults/write