where rules determine what is allowed access to an object eg firewalls ruleset