cft policiesAmazon EC2 InstanceUpdated 7 months ago Ensure that the S3 bucket has object lock enabledEnsure that the root block device has encryption enabledAsk AI