The policy [here](https://github.com/terraform-ibm-modules/terraform-ibm-icd-mysql/blob/2530dcc132f1c494d1d5e8b31ffbd7100b8fa544/main.tf#L36-L45) can be updated to scope it to the exact KMS key. For an example of the syntax, see https://github.com/terraform-ibm-modules/terraform-ibm-cos/pull/764