Disclosed is an access and information flow control framework. The framework includes: creating consistent and conflict-free authorization requirement(s) from the raw authorization requirement(s); creating consistent case authorization(s); creating information flow and propagated information flow requirement(s) that are consistent with an information flow policy; creating operation authorization(s); resolving inconsistencies in operation authorization(s); and ensuring that the operation authorization(s) are conflict-free.