5.1 Security Considerations for Implementers

A central access policy defines an authorization policy that controls access to resources. Write permissions on central access policies enable a user to modify the authorization policy. Central access control policies are designed to be managed centrally and not be edited on client computers. Therefore, it is important to store central access control policies on client computers in secure locations to which only system processes have access.