I received the September issue of the ISSA Journal . It contains several useful articles, with the most helpful to me being a humanly readable summary of the Common Criteria by Alex Ragen . I don't think Mr. Ragen clearly states who needs to purchase Common Criteria-validated products however. His article's first sentence states: "On July 1, 2002, the US Department of Defense began to enforce National Security Telecommunications and Information Systems Security Policy (NSTISSP) #11 (issued in January 2000), which mandates that US government agencies purchase only those IT security products which have been validated in accordance with Common Criteria and/or FIPS 140-1 or FIPS 140-2 as appropriate." He also says: "As mentioned earlier, US government agencies now require Common Criteria certification." This is not true. According to the Committee on National Security Systems FAQ : "The policy mandates, effective 1 July 2002, that departments and agen...