<?xml version="1.0" encoding="UTF-8"?><PolicySet xmlns="urn:oasis:names:tc:xacml:2.0:policy:schema:os" PolicyCombiningAlgId="urn:oasis:names:tc:xacml:1.0:policy-combining-algorithm:permit-overrides" PolicySetId="TestRoleCentricPEP" Version="1">
  <Description>TestRoleCentricPEP</Description>
  <PolicySetDefaults>
    <XPathVersion>http://www.w3.org/TR/1999/Rec-xpath-19991116</XPathVersion>
  </PolicySetDefaults>
  <Target>
    <Subjects>
      <Subject>
        <SubjectMatch MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
          <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">Music</AttributeValue>
          <SubjectAttributeDesignator AttributeId="urn:com:soffid:xacml:subject:primaryGroup" DataType="http://www.w3.org/2001/XMLSchema#string"/>
        </SubjectMatch>
      </Subject>
    </Subjects>
  </Target>
  <Policy PolicyId="RoleCentricPolicy" RuleCombiningAlgId="urn:oasis:names:tc:xacml:1.0:rule-combining-algorithm:permit-overrides" Version="1">
    <Description>RoleCentricPolicy</Description>
    <PolicyDefaults>
      <XPathVersion>http://www.w3.org/TR/1999/Rec-xpath-19991116</XPathVersion>
    </PolicyDefaults>
    <Target>
      <Resources>
        <Resource>
          <ResourceMatch MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
            <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">role</AttributeValue>
            <ResourceAttributeDesignator AttributeId="com:soffid:iam:xacml:1.0:resource:soffid-object" DataType="http://www.w3.org/2001/XMLSchema#string"/>
          </ResourceMatch>
        </Resource>
      </Resources>
    </Target>
    <VariableDefinition VariableId="iSystem">
      <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">ERP RRHH</AttributeValue>
    </VariableDefinition>
    <Rule Effect="Permit" RuleId="PermitQuery">
      <Description>Permit Query</Description>
      <Target>
        <Actions>
          <Action>
            <ActionMatch MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
              <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">query</AttributeValue>
              <ActionAttributeDesignator AttributeId="urn:com:soffid:xacml:action:method" DataType="http://www.w3.org/2001/XMLSchema#string"/>
            </ActionMatch>
          </Action>
        </Actions>
      </Target>
    </Rule>
    <Rule Effect="Deny" RuleId="DenyUpdate">
      <Description>Deny Update</Description>
      <Target>
        <Actions>
          <Action>
            <ActionMatch MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
              <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">update</AttributeValue>
              <ActionAttributeDesignator AttributeId="urn:com:soffid:xacml:action:method" DataType="http://www.w3.org/2001/XMLSchema#string"/>
            </ActionMatch>
          </Action>
        </Actions>
      </Target>
      <Condition>
        <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
          <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-one-and-only">
            <AttributeSelector DataType="http://www.w3.org/2001/XMLSchema#string" RequestContextPath="/informationSystem/name"/>
          </Apply>
          <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-one-and-only">
            <VariableReference VariableId="iSystem"/>
          </Apply>
        </Apply>
      </Condition>
    </Rule>
    <Rule Effect="Deny" RuleId="DenyDelete">
      <Description>Deny Delete</Description>
      <Target>
        <Actions>
          <Action>
            <ActionMatch MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
              <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">delete</AttributeValue>
              <ActionAttributeDesignator AttributeId="urn:com:soffid:xacml:action:method" DataType="http://www.w3.org/2001/XMLSchema#string"/>
            </ActionMatch>
          </Action>
        </Actions>
      </Target>
    </Rule>
    <Rule Effect="Deny" RuleId="DenyCreate">
      <Description>Deny Create</Description>
      <Target>
        <Actions>
          <Action>
            <ActionMatch MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
              <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">create</AttributeValue>
              <ActionAttributeDesignator AttributeId="urn:com:soffid:xacml:action:method" DataType="http://www.w3.org/2001/XMLSchema#string"/>
            </ActionMatch>
          </Action>
        </Actions>
      </Target>
    </Rule>
  </Policy>
</PolicySet>
