An IS auditor reviewing a financial system finds that users can access any record regardless of their department.Which access control model is MOST appropriate to remediate this?