Permissions
The GCP CIS v2.0.0 - Section 4 - Virtual Machines policy pack requires 7 permissions:
compute.disks.deletecompute.instances.deletecompute.instances.deleteAccessConfigcompute.instances.setMetadatacompute.instances.stopcompute.instances.updateShieldedInstanceConfigcompute.projects.setCommonInstanceMetadata