---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Creating rules for application vulnerable items in the Software Bill of Materials Workspace

# Creating rules for application vulnerable items in the Software Bill of Materials Workspace {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Creating Rules for Application Vulnerable Items in the Software Bill of Materials Workspace

To effectively manage application vulnerable items (AVITs) in the Software Bill of Materials (SBOM) Workspace, it is essential to establish creation rules that determine when AVITs are generated.
AVITs are created based on conditions defined by existing rules when data from SBOM files is imported.
The SBOM Response and Vulnerability Response applications must be activated to automate this process.
Show full answer Show less  

## Key Features

* **AVIT Creation Rules:** Users with the snsbomresp.manageavirule role can create rules that trigger the generation of AVITs, allowing for the assessment of third-party component vulnerabilities.
* **SBOM Workspace Integration:** AVITs can be viewed in the SBOM Workspace and the Vulnerability Manager Workspace, providing a comprehensive view of vulnerabilities.
* **Remediation Management:** AVITs can be assigned for remediation based on recommendations from known vulnerability lists, and tasks are automatically created for remediation efforts.
* **Automatic Reopening of AVITs:** Closed AVITs can automatically reopen if the associated vulnerabilities are detected again or included in a new SBOM upload, maintaining up-to-date visibility on vulnerabilities.

## Key Outcomes

By establishing AVIT creation rules, ServiceNow customers can ensure proactive management of vulnerabilities in their applications. Customers can expect enhanced tracking and remediation capabilities for third-party components, leading to improved application security and integrity. Additionally, the automatic reopening of AVITs helps maintain a current understanding of vulnerabilities, ensuring that remediation efforts are timely and efficient.  
Before you can see application vulnerable items (AVITs) in the Software Bill of Materials (SBOM) Workspace, you must set up the conditions under which AVITs are created.

## AVITs in the SBOM Workspace {#vr-sbom-config-sbom-response__section_djm_b1z_yxb}

If you've installed and activated the SBOM Response application, AVITs are created for SBOM files if any of the imported data matches the conditions of your existing AVIT creation rules.

The SBOM Response and Vulnerability Response applications are required to set up rules for creating application vulnerable items (AVITs) automatically and remediating them with the Application Vulnerability Response workflow. See [Exploring Software Bill of Materials](https://servicenow-prod.fluidtopics.net/8LjPHeECHwD3bz2tvjiDFg "Identify the components used in your organization's applications from Software Bill of Materials (SBOM) files you upload into your instance. Understand any risks associated with using open-source software to help you determine your potential exposure, view license compliance, and fix vulnerabilities.") for more information.

As a user with the sn_sbom_resp.manage_avi_rule role, you must add AVIT creation rules in the SBOM Workspace before you can create AVITs for the vulnerabilities that are found in your ingested SBOM data. AVITs enable you to evaluate the integrity of the third-party components in your applications. An AVIT is created in your instance when an application is matched to a component that has an
associated vulnerability.

In the SBOM Workspace, you can view only SBOM AVITs. However You can view SBOM AVITs along with other types of vulnerable items in the Vulnerability Manager Workspace in Vulnerability Response. You can view all the AVITs that have been created in the SBOM Workspace in the List Module. The list module also includes all the NVD and CWE entries and Application Vulnerabilities.

You can also assign AVITs for remediation based on recommendations from known vulnerability lists such as the National Vulnerability Database (NVD). A scheduled job is triggered, and if the conditions of your creation rules
match the ingested data, AVITs are created.

You can track and remediate AVITs by setting up customized rules.

See [Create an application vulnerable item rule in the Software Bill of Materials Workspace](https://servicenow-prod.fluidtopics.net/5Ma1DQ~AU1W4zj5TYbB7jg "Set up the conditions under which application vulnerable items (AVITs) are created automatically in the AVI Creation Rules module in the Software Bill of Materials (SBOM) Workspace.") for information about how to create a rule.

## SBOM AVITs in Vulnerability Manager Workspace in Vulnerability Response

You can view any SBOM AVITs that are created in the SBOM Workspace in the Vulnerability Manager Workspace if you have access to it.  
Note:  
To view only SBOM AVITs from the Application Vulnerable Items list in the Vulnerability Manager Workspace rather than all AVITs, set the condition \[Source\] \[is\] \[SBOM\] AND \[Scan type\] \[is\] \[SBOM-SCA\] on the Application Vulnerable Items \[sn_vul_app_vulnerable_item\] table. To view the table, navigate in your instance to All and enter sn_vul_app_vulnerable_item.list in the filter navigator.

For
more information about the Vulnerability Manager Workspace, how to view watch topics, application remediation efforts, and application remediation task rules for AVITs that are configured from the Vulnerability Response application in the Vulnerability Manager Workspace, see [Use watch topics in the Vulnerability Manager Workspace](https://servicenow-prod.fluidtopics.net/q0woJTRFYEdyoCVrrq_Fpg "Use watch topics in the Vulnerability Manager Workspace to view vulnerabilities and misconfigurations that are filtered from your imported data from the criteria that you set. Use this information to determine how the vulnerabilities and misconfigurations in each watch topic can impact your environment.").

Remediation tasks (AVULs) are created from AVITs and assigned automatically to groups for remediation based on your assignment rules. For more information about how to create these rules, see the following topics:

* [Create or edit Vulnerability Response assignment rules](https://servicenow-prod.fluidtopics.net/~F6X16AyH_Z7pLhpvkyLfA "After you complete your initial assessment of assignment rules using Setup Assistant, you can create rules to automatically assign vulnerable items based on filter conditions. These rules assign vulnerable items as they are imported or manually created.")
* [Create or edit Vulnerability Response remediation task rules](https://servicenow-prod.fluidtopics.net/gjnIR~u_kUymvXKMt0Lqng "After you complete your initial assessment of remediation task rules using Setup Assistant, you can create rules to automatically group vulnerable items based on filter conditions. These rules automatically group vulnerable items as they are imported or manually created. Use the filter to limit the vulnerable items grouped by this rule, such as selecting all vulnerable items with exploits.") and [Create a remediation effort in the Vulnerability Manager Workspace](https://servicenow-prod.fluidtopics.net/466ujNvBHGELqdSIBD3Bbw "A remediation effort record is a static list of records that you create from a watch topic in the Vulnerability Manager Workspace.").
{#vr-sbom-config-sbom-response__ul_ob5_3xy_yxb}

## Reopening application vulnerable items in SBOM Response {#vr-sbom-config-sbom-response__section_sty_t1s_tcc}

A Closed application vulnerable item (AVIT) for a component with an associated vulnerability is re-opened automatically and visible in the SBOM Workspace if the following conditions exist:

* The AVIT with the associated vulnerability is detected again by a third-party integration's vulnerability scans or the component with the vulnerability is part of a subsequent SBOM upload.
* You have not deactivated the Reopen AVITs if detected (sn_sbom_resp.reopen_avits_if_detected) system property. This system property is activated by default.
* The substate of the Closed AVIT is not one of the following: Mitigation Control in Place, Not Affected, or False Positive. AVITs with these substates are not reopened by the system property.
{#vr-sbom-config-sbom-response__ul_k2z_r1s_tcc}

Deactivate this system property only if you do not want Closed AVITs to reopen automatically.

