Improve IAM resources as it has been done in Lambda module (see this PR - https://github.com/terraform-aws-modules/terraform-aws-lambda/pull/195 )