You can do this by setting up specific privilege levels and associating specific privilege levels with specific commands
http://www.cisco.com/en/US/docs/ios/12_2/security/command/reference/srfpass.html#wp1017387
As the security specialist for your company you want to ensure employees don't get more access than they need to. At this moment everyone is logging in using privilege level 15 for your routers and you want to ensure this doesn't happen anymore in the future.
c3640-jk9s-mz.124-16.bin

You need to register to download the GNS3 Topology File. (Registration is Free!)