What is a “Security Policy?”
What rights MAY a user have?
Define the maximum!
What rights can a user pass on?
How can a user acquire additional rights?
Linux/Unix:   -rwxr-xr--   /foo
        -rw--w----   /bar