The referenced statement was specified by David: section 7.15,
"Authorization Decsion."
After reading this section 7.15 (I did not find it when skimming over
the spec - thanks@David), I think there is no implicit top level
PolicySet, but rather a top level Policy Combining Algorithm, which is a
property of the PDP (which should/could be configurable). Anyhow, how
it is determined ("hard-coded" or configurable) is implementation
dependent.
Regards,
Helmut
On 07/18/2011 09:44 PM, rich levinson wrote: