---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create an application vulnerable item rule in the Software Bill of Materials Workspace

# Create an application vulnerable item rule in the Software Bill of Materials Workspace {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Set up the conditions under which application vulnerable items (AVITs) are created automatically in the AVI Creation Rules module in the Software Bill of Materials (SBOM) Workspace.

## Before you begin

The SBOM Response application is required if you want to create application vulnerable items. See [Exploring Software Bill of Materials](https://servicenow-prod.fluidtopics.net/8LjPHeECHwD3bz2tvjiDFg "Identify the components used in your organization's applications from Software Bill of Materials (SBOM) files you upload into your instance. Understand any risks associated with using open-source software to help you determine your potential exposure, view license compliance, and fix vulnerabilities.") for more information.

Role required: sn_sbom_resp.manage_avi_rule.

## Procedure

1. Navigate to SBOM WorkspaceAVI Creation Rules.
2. Select New.
3. Fill out the fields.  
   {#vr-sbom-create-avi-rule__table_kdg_gbq_xzb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the rule. |
   | Active | Indicates whether the creation rule is activated. |
   | Execution order | Order in which the rules are evaluated. The rule with the lowest numerical value runs first. For example, you might create higher priority rules for items that need special handling, or where risk is critical, so they are run first. Next, create general rules for items that require no special handling. Finally, create a default rule to catch any components that have vulnerabilities. |
   | Description | Description of the rule to help you distinguish it from other rules. |
   | Conditions | Create the conditions under which application vulnerable items (AVIs) are created. For example, you might select \[Vulnerability \> Severity\]\[is\]\[1-Critical\] to create AVITs for components that have vulnerabilities that are high-risk and might severely impact you. Note that you can add more conditions. |
   [ ]

   {#vr-sbom-create-avi-rule__table_kdg_gbq_xzb}
4. Select Save.  
   Your creation rule runs automatically after the next upload and creates AVIs for components that match your conditions. You can also run the rule on-demand from the AVI Creation Rules module by selecting Execute Now.

## Result

After they are created, you can verify that an AVIT was created specifically for SBOM data by checking the values in the Source and Scan type fields on an AVI record.  
{#vr-sbom-create-avi-rule__table_bmg_1zy_yxb__entry__2}

| Field | Value |
|-|-|
| Source | SBOM |
| Scan type | SBOM-SCA |
[ ]

{#vr-sbom-create-avi-rule__table_bmg_1zy_yxb}

*[\>]: and then


