Logical access control by restricting access to objects based on the identity of subjects or their belonging groups.