How to use least privileges with AWSLambdaBasicExecutionRole

This guy wrote typicalrunt.me » Enforcing Least Privilege When Logging Lambda Functions to CloudWatch on how he fixed it with cloudformation