ACLs for a group

I use LDAP to storage users accounts and groups, but I don't understand
very well the rules of ACLs and I need to create a ACL to permit all
users in certain group (eg. admin) to modify information of all users in
other group (eg. users). 
My users and groups stay in different Organization Units, and user
refers to group through the attribute groupNumber.
Does anyone have any idea how can I do this?

André Luís Fogagnoli
Bastion Security Systems