When determining whether or not access by a user should be permitted by
using policies, an access control determination device of the present
invention expresses the access by the user to the data source with a
predetermined path, retrieves an appropriate policy out of stored
policies on the basis of the predetermined path, calculates an access
permission value on the basis of the predetermined path, calculates an
access effect value on the basis of the predetermined path and the policy
which the policy retrieving unit has retrieved, and determines whether or
not the access by the user to the data source should be permitted on the
basis of the access permission value and the access effect value.