To add access check rules and policies, use the Attribute-Based Access Control section on the navigation panel.
NOTE. When roles of information security administrator and application administrator are separated, the Attribute-Based Access Control section is available only for information security administrator. Attribute-based access control structure creation (attribute addition, policy and rules editing) is controlled by the system and is available to the administrator with the Changing User Permissions, Distributing Roles, Changing Policy privilege and the Changing Security Label and Access Control List of Any Object privilege.
The section is based on the attribute-based access control method, it is used to create access check rules with necessary conditions. The system checks if a user can execute a specific action on an object and/or data segment through an attribute check.
NOTE. The attribute-based access control method can be used simultaneously with the discretionary access control method.
Attributes are divided into system and custom, they are used when creating a objective and additional conditions of access check. System attributes are read-only, only custom attributes can be added or edited for users, user groups, object classes, particular object types, particular objects depending on the defined task.
NOTE. Custom attributes are added before getting started with the section.
Make sure that the Use Attribute-Based Access Control checkbox is selected in the access control.
The Attribute-Based Access Control:


The section contains a structure of attribute-based access control that consists in the elements hierarchy:
Attribute-Based Access Control is at the first level, the structure of sets of policies, policies and rules is determined here.
Sets of policies are at the second level.
Policies are at the third level.
Rules are at the fourth level.
IMPORTANT. If attribute-based access control structure is not set, all operations on objects are denied.
Key features:
Determine attribute-based access control properties
To create an access check policy:
Make sure that the required attributes are added for users, user groups, object classes, particular types of objects, particular objects.
Add a set of policies that unites policies and sets of policies in one condition.
Add a policy containing access check conditions.
Add a rule containing additional access check conditions.
Set properties determining access to objects.
Determine structure of access control using checkboxes next to attribute-based access control elements.
Save the specified access check policy:
In the web application click the Save button on the side panel.
In the desktop application click the
Save button on the toolbar.
After creating an access check policy the section will display attribute-based access structure.
To optimally place attribute-based access control elements in the structure, use the
Up and
Down buttons or Drag&Drop mechanism.
If required, delete the attribute-based access control elements using the Delete button.
See also:
Setting Up Attribute-Based Access Control Method | Creating Custom Attributes