A policy storage stores an access control policy as a set of setting
information items to make resources (access destinations) shared by an
adhoc group. When a part of the access control policy is edited, a policy
analyzer updates a rule generated from the edited access control policy.
At this time, the rule is updated with use of object knowledge having a
data configuration capable of expressing a user as belonging to plural
user groups. An access control list setting means updates a part of an
access control list, based on the updated rule. Accordingly, an access
control list can be generated with respect to a user group including a
user who belongs to plural organizations, and the access control list can
be updated efficiently.