Create a new SCP to deny public buckets except for known exemptions. https://github.com/cds-snc/cds-aws-lz/blob/main/terragrunt/org_account/organization/scp.tf