In the context of cooperative information systems, research focused on the interoperability among data sources, related to schematic and syntactic representations or semantic expression. Security introduces new problems of heterogeneity. In this paper we refer to the different ways to represent authorization and rules in access control policies. Our proposition consists in using a role based multy-policy model to represent heterogeneous policy in the same formalism. We also map the local policies creating access bridges and we propose a set of security controls to filter a global user query.