To add access check rules and policies, use the Attribute-Based Access Control section on the navigation panel:

Make sure that the Use Attribute-Based Access Control checkbox is selected in the access control.
NOTE. When roles of the information security administrator and the application administrator are separated, the Attribute-Based Access Control section is available only for the information security administrator. Attribute-based access control structure creation (attribute addition, policy and rules editing) is controlled by the system and is available to the administrator with the Changing User Permissions, Distributing Roles, Changing Policy and the Changing Security Label and Access Control List of Any Object privileges.
The section is based on the attribute-based access control method, it is used to create access check rules with necessary conditions. The system checks if a user can execute a specific action with an object and/or data segment through an attribute check.
NOTE. The attribute-based access control method can be used simultaneously with the discretionary access control method.
Attributes are divided into system and custom, they are used when creating a objective and additional conditions of access check. System attributes are read-only, only custom attributes can be added or edited for users, user groups, object classes, particular object types, particular objects depending on the objective.
NOTE. Custom attributes are added before getting started with the section.
The section contains the attribute-based access control structure that includes the elements hierarchy:
Attribute-Based Access Control is at the first level, the structure of sets of policies, policies and rules is determined here.
Sets of policies are at the second level.
Policies are at the third level.
Rules are at the fourth level.
IMPORTANT. If attribute-based access control structure is not set, all operations with objects are denied.
Key features:
Determine attribute-based access control properties
To create an access check policy:
Make sure that the required attributes are added for users, user groups, object classes, particular types of objects, particular objects.
Add a set of policies that unites policies and sets of policies in one condition.
Add a policy containing access check conditions.
Add a rule containing additional access check conditions.
Set properties that determine access to objects.
Determine structure of access control using checkboxes next to attribute-based access control elements.
Click the Save button on the side panel to save the specified access check policy.
After creating an access check policy the section will display attribute-based access structure.
To optimally place attribute-based access control elements in the structure, use the
Up and
Down buttons or Drag&Drop mechanism.
If required, delete attribute-based access control elements using the
Delete button.
See also:
Setting Up Attribute-Based Access Control Method | Creating Custom Attributes