Suggestion for rds parameter to be resolved during plan rather than at apply for sentinel policy to resolve it

We are using aws_rds_cluster_parameter_group from terraform to create parameter group and sentinel policy is failing to pick the rds.force_ssl parameter during the plan. Please suggest how to resolve so that sentinel policy can pick the parameter before we apply the changes.