Permissions
The GCP CIS v2.0.0 - Section 4 - Virtual Machines policy pack requires 7 permissions:
compute.disks.delete
compute.instances.delete
compute.instances.deleteAccessConfig
compute.instances.setMetadata
compute.instances.stop
compute.instances.updateShieldedInstanceConfig
compute.projects.setCommonInstanceMetadata