Permissions
The GCP CIS v2.0.0 - Section 1 - Identity and Access Management policy pack requires 6 permissions:
apikeys.keys.deletecloudkms.cryptoKeys.setIamPolicydataproc.clusters.deleteiam.serviceAccountKeys.deleteiam.serviceAccounts.deleteresourcemanager.projects.setIamPolicy