Which combination of steps will meet these requirements?
(Choose three.)
Enable trusted access for CloudFormation with Organizations by using service-managed permissions.
Create an IAM role that is named AWSControlTowerBlueprintAccess. Configure the role with a trust policy that allows the AWSControlTowerAdmin role in the management account to assume the role. Attach the AWSServiceCatalogAdminFullAccess IAM policy to the AWSControlTowerBlueprintAccess role.
Create a Service Catalog product for each CloudFormation template.
Create a CloudFormation stack set for each CloudFormation template. Enable automatic deployment for each stack set. Create a CloudFormation stack instance that targets specific OUs.
Deploy the Customizations for AWS Control Tower (CfCT) CloudFormation stack.
Create a CloudFormation template that contains the resources for each customization.