An access control system and method includes a risk index module which
computes a risk index for a dimension contributing to risk. A boundary
range defined for a parameter representing each risk index such that the
parameter above the range is unacceptable, below the range is acceptable
and in the range is acceptable with mitigation measures. A mitigation
module determines the mitigation measures which reduce the parameter
within the range.