Describe what access control model can represent the following two security policies:
a. Administrators only can create and delete patient records.
b. Administrators only can create and delete patient records, but Administrators can do this only between office hours, i.e. Only between 9.00 am to 4.00 pm.
Describe the policy components (subject, access rights and objects etc.)