**RuBAC** is applied using a set of rules, or access control lists (**ACLs**), that apply to various objects or resources. When an attempt is made to access an object, the rule is checked to see if the access is allowed. A common example of a rule-based access control is a *firewall ruleset*.