Activate SBOM support
Install the required applications and verify prerequisites to enable SBOM collection in Third-party Risk Management (TPRM).
Before you begin
- Verify that the Smart Assessment Engine is enabled. SBOM collection is not supported for Classic assessments.
- Check your entitlements to determine whether you have access to this application and all associated ServiceNow Store applications. For more information, see Get entitlement for a ServiceNow product or application.
Role required: admin
About this task
An SBOM (Software Bill of Materials) is a structured inventory of the software components in a product. In TPRM, SBOM collection is performed through engagement-level external assessments using the Smart Assessment Engine. Installing the core SBOM applications makes the required data structures and processing capabilities available in your instance. Installing the optional vulnerability response applications adds vulnerability context for individual SBOM components.
Procedure
Navigate to All > System Applications > All Available Applications > All.
Install the required SBOM applications.
Find each application using the filter criteria and search bar, then select Install for each one.
Application ID SBOM Core sn_sbom_coreData Model for SBOM sn_sbom_dmCore SBOM data structures and processing capabilities are available in the instance.
Install the optional vulnerability response applications if you require vulnerability insights for SBOM components.
Find each application using the filter criteria and search bar, then select Install for each one.
Application ID SBOM Response sn_sbom_respVulnerability Response sn_vulNote: These applications enable vulnerability context for SBOM components but are not required to collect SBOM files.
Verify that SBOM fields and related lists are available on an engagement record.
Navigate to the Vendor Management Workspace using one of the following methods:
- Select Workspaces > Vendor Management Workspace.
- Navigate to All > Third-party Risk Management > Vendor Management Workspace.
- Open an engagement record.
Confirm that the SBOM required field is visible on the engagement record, and that the SBOM document related list appears on the engagement.
The instance is ready to collect SBOM information through engagement-level external assessments.
What to do next
After installing SBOM support, you can request an SBOM from a third party through an engagement-level external assessment. For next steps, see Request a software bill of materials from an engagement.
Related topics
Exploring software bill of materials collection
Collecting software bill of materials
Request a software bill of materials from an engagement
Review an SBOM submission from an engagement
SBOM records and relationships in Third-party Risk Management