All statements in all S3 bucket policies must have a condition that requires encryption at a certain level
S3 buckets support numerous types of encryption, including AES-256, KMS using a default key, KMS with a CMK, or via HSM-based key.
Configure a bucket policy to enforce encryption.