Am I reading this correctly:
If I add/update/remove from the security group list for the referenced FSx that CloudFormation will blow away the whole referenced FSx, data and all, to recreate it?
If that's the case, what is the way to manage what systems would have access to the referenced FSx without destroying all of the data?