Not too sure if every system automatically has these difference kinds of accounts.
Sure, the node of a corporate site will have these, but a single-user commink?
I know my cell-phone only has an admin account, no others.
If not, I'd agree on user -usually- being high enough to write a file... but it's up to the admin to set these restrictions; for a single-user device I'd think it makes sense to for the admin-user disallow anything that's not your own level.
Security accounts shutting down security is a big no-no, even for corporate accounts imo. They can call in IC, kick/temp-block user-level accounts and maybe manage some smaller settings and shut down low-level operations to make sure the security programs get priority, but actually disabling security on a node should definately be a admin-only right.