This presentation introduces Common CriteriaNIAPNSTISSP No. 11computer security evaluation concepts , in particular the , the , and key U.S. policies such as . It then discusses security in open source software, and some of the challenges for open source software in dealing with them.