Methods and systems are provided for defining and creating an automatic
file security policy and a semi-automatic method of managing file access
control in organizations with multiple diverse access control models and
multiple diverse file server protocols. The system monitors access to
storage elements within the network. The recorded data traffic is
analyzed to assess simultaneous data access groupings and user groupings,
which reflect the actual organizational structure. The learned structure
is then transformed into a dynamic file security policy, which is
constantly adapted to organizational changes over time. The system
provides a decision assistance interface for interactive management of
the file access control and for tracking abnormal user behavior.