to allow updates to DDB: (update stack-name as needed)
aws cloudformation set-stack-policy --stack-name STACK_NAME --stack-policy-body '{"Statement":[{"Effect":"Allow","Principal":"","Action":["Update:"],"Resource":""},{"Effect":"Allow","Principal":"","Resource":"*","Condition":{"StringEquals":{"ResourceType":["AWS::DynamoDB::Table"]}},"Action":["Update:Replace"]}]}'
To disable updates to DDB:
aws cloudformation set-stack-policy --stack-name STACK_NAME --stack-policy-body '{"Statement":[{"Effect":"Allow","Principal":"","Action":["Update:"],"Resource":""},{"Effect":"Deny","Principal":"","Resource":"*","Condition":{"StringEquals":{"ResourceType":["AWS::DynamoDB::Table"]}},"Action":["Update:Replace"]}]}'