A method and system for combining and enforcing security policies is
provided. The security system is provided with security policies that
have process set criteria and associated rules. The security system
combines the security policies by generating a rule list of the security
policies and associated process set criteria. The rules of the rule list
are ordered based on rule type and action of the rule. When a new process
is started to execute an application, the security system determines the
process set criteria that are satisfied by the application. The security
system then identifies the rules of the rule list that are associated
with the satisfied process set criteria. When a security enforcement
event associated with the process occurs, the security system applies
each of the rules associated with the process to the security enforcement
event in an order specified by the rule list.