The policy [here](https://github.com/terraform-ibm-modules/terraform-ibm-secrets-manager/blob/54a3274a850cc492bf394e69ee28dc53f8b645ff/main.tf#L64-L72) and [here](https://github.com/terraform-ibm-modules/terraform-ibm-secrets-manager/blob/54a3274a850cc492bf394e69ee28dc53f8b645ff/solutions/standard/main.tf#L41-L51) can be updated to scope it to the exact KMS key. For an example of the syntax, see https://github.com/terraform-ibm-modules/terraform-ibm-cos/pull/764