In a medium - sized company, the IT department manages access to various systems and resources for employees. The team wants to enhance the security posture by implementing better access controls. They use rule - based access controls and time - of - day restrictions to achieve this goal. What are the IT department's objectives in implementing rule - based access controls and time - of - day restrictions? ( Select the two best options. )
A . To define specific access rules based on employees' roles and responsibilities
B . To eliminate the need for user authentication and simplify access management
C . To ensure all employees have access to all resources at any time for increased productivity
D . To restrict access to critical systems during non - working hours to enhance security