See documentation https://tfsec.dev/docs/aws/AWS068/ Our current configuration is set this way, is this enough? https://github.com/cds-snc/notification-terraform/blob/a5dfb25131a9b61a65233a4712b80c79d9bff85a/aws/eks/eks.tf#L11-L16 @maxneuvians can you advise and maybe even propose a PR?