---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Install supported applications

# Install the supported applications for Software Bill of Materials {#ariaid-title1}

* Release version: Australia
* 
* Updated April 3, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Download and activate the required applications for the Software Bill of Materials (SBOM) application prior to uploading files.

## Before you begin

Roles required: admin for download, installation, and activation of all applications and role assignments in your instance.

## About this task

## Procedure

1. Download the required SBOM applications from the ServiceNow Store into your ServiceNow instance.  
   These applications enable you to upload and import SBOM files into your instance. You can view BOM entity and component data in the SBOM Workspace if you have SBOM Core installed.

   You can view BOM entity, component data, and data visualizations in the SBOM Workspace if you have SBOM Response installed.
   * Data Model for SBOM
   * SBOM Core

   {#vr-sbom-install-apps__ul_ylb_xmr_5zb}  
   For more information about downloading and activating applications, see the following:
   * [Install a ServiceNow Store application](https://www.servicenow.com/docs/access?context=t_InstallApplications&version=australia&pubname=australia-platform-administration&ft:locale=en-US)
   * [Install an update to a ServiceNow Store application](https://www.servicenow.com/docs/access?context=t_InstallUpdates&version=australia&pubname=australia-platform-administration&ft:locale=en-US)
   {#vr-sbom-install-apps__ul_l4j_jpg_b1c}
2. **Optional:** If you want to view your SBOM data in the SBOM Workspace, view imported third-party vulnerability intelligence, assess your risk exposure, and remediate vulnerabilities with the Application Vulnerability Response and Vulnerability Response workflows, download the following applications:  
   * Vulnerability Response and its dependencies
   * Vulnerability Response Integration with NVD
   * SBOM Response

   {#vr-sbom-install-apps__ul_fn2_qrh_xzb}

   For more information about these and other supported SBOM applications, see [Exploring Software Bill of Materials](https://servicenow-prod.fluidtopics.net/8LjPHeECHwD3bz2tvjiDFg "Identify the components used in your organization's applications from Software Bill of Materials (SBOM) files you upload into your instance. Understand any risks associated with using open-source software to help you determine your potential exposure, view license compliance, and fix vulnerabilities.").
3. After you have downloaded the applications, navigate to AllSystem ApplicationsAll Available ApplicationsAll.
4. Locate the SBOM applications that you downloaded and select Install to activate them along with their dependencies.  
   A message is displayed after an application is successfully activated. Activate the applications in the following order:
   * Vulnerability Response and its dependencies
   * Vulnerability Response Integration with NVD
   * Data Model for SBOM
   * SBOM Core
   * SBOM Response, which includes the OSV.dev and Deps.dev integrations and supports the Policy as Code Engine (PaCE) interface in the SBOM Workspace.

   {#vr-sbom-install-apps__ul_gvg_sry_yxb}

   See [Configuring the Deps.dev, OSV.dev, and PaCE integrations for Software Bill of Materials](https://servicenow-prod.fluidtopics.net/pT6RGXKjAqqpjOdiID8GCg "You can edit some of the parameters for the Deps.dev and OSV.dev integrations. There are also two code trigger versions of these integrations that are used strictly for internal workflows, and you should not initiate these integrations on-demand. Additionally, you can activate a scheduled job to create policies using Policy as Code Engine (PaCE).") for more information about configuring these integration applications after you have installed SBOM Response.
5. **Optional:** Activate integrations by navigating to AllSystem ApplicationsAll Available ApplicationsAll and selecting Install.  
   For more information about these integrations and the capabilities they provide, see [Exploring Software Bill of Materials](https://servicenow-prod.fluidtopics.net/8LjPHeECHwD3bz2tvjiDFg "Identify the components used in your organization's applications from Software Bill of Materials (SBOM) files you upload into your instance. Understand any risks associated with using open-source software to help you determine your potential exposure, view license compliance, and fix vulnerabilities.").
   * Vulnerability Response Integration with Veracode. See [Install the ServiceNow Vulnerability Response Integration with Veracode](https://servicenow-prod.fluidtopics.net/VT7QKPT8AdrIFhShPfi4NA "Before you run the integration on your instance, the installation and configuration steps must be completed so the Veracode product properly integrates with Application Vulnerability Response. This application is available as a separate subscription.") for more information.
   * Vulnerability Response Integration with NVD, which is required if you want to view the enhanced data for vulnerabilities associated with uploaded components. See [Understanding the NVD integrations](https://servicenow-prod.fluidtopics.net/eFiXOlP4oTeyfPz4Q0roQA "The NVD integrations use data imported from the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) product to help you determine the impact and priority of flaws in your code. Run this integration as part of your initial setup of Vulnerability Response and prior to importing vulnerability data into your instance with a third-party scanner product.") for more information.
   * CWE Comprehensive 2000 Integration. See [Configure and run the scheduled job for updating CWE records](https://servicenow-prod.fluidtopics.net/eW08j7C7hKeJNiT7jgbPMg "Data imports from the CWE further enrich the vulnerability data in your instance. Use Common Weakness Enumeration (CWE) records downloaded from the CWE database for reference when deciding whether a vulnerability must be escalated. Run this integration as part of your initial setup of Vulnerability Response and prior to importing vulnerability data into your instance with a third-party scanner product.") for more information about activating this scheduled job.

   {#vr-sbom-install-apps__ul_uz1_f42_dzb}

   A message is displayed after an application is successfully activated.
6. Assign the following roles to users.  
   * sn_sbom_dm.app_create
   * sn_sbom_dm.app_read
   * sn_sbom_dm.app_write
   * sn_sbom_core.sbom_ingest
   * sn_sbom_core.admin
   * sn_sbom_resp.sbom_analyst
   * sn_sbom_resp.manage_avi_rule
   * sn_sbom_response.managelicense
   * sn_sbom_response.licenseresolver
   {#vr-sbom-install-apps__ul_a24_wqv_zyb}
7. **Optional:** Assign users to the App-Sec Manager group if you are creating application vulnerable items for vulnerabilities in your imported SBOM data.  
   Users assigned to the App-Sec Manager group prioritize and manage application vulnerable items. Users in this group inherit many of the roles required for reading and editing records and configuring the applications
   supported by the Application Vulnerability Response application and its remediation workflows.
8. **Optional:** Deactivate the Reopen AVITs if detected (sn_sbom_resp.reopen_avits_if_detected) system property if you don't want Closed AVITs to transition back to the Open state automatically.  
   A Closed application vulnerable item (AVIT) for a component with an associated vulnerability is re-opened (set to Open) automatically and visible in the SBOM Workspace if
   the following conditions exist:
   * The AVIT with the associated vulnerability is detected again by a third-party integration's vulnerability scans or the component with the vulnerability is part of a subsequent SBOM upload.
   * You have not deactivated the Reopen AVITs if detected (sn_sbom_resp.reopen_avits_if_detected) system property. This system property is activated by default.
   * The substate of the Closed AVIT is not one of the following: Mitigation Control in Place, Not Affected, or False Positive. AVITs with these substates are not reopened by the system property.
   {#vr-sbom-install-apps__ul_tty_wtr_tcc}
{#vr-sbom-install-apps__steps_oqm_tqc_rxb}

## What to do next

Upload your SBOM files. See [Upload Software Bill of Materials files manually](https://servicenow-prod.fluidtopics.net/gC68MpRjc2RiCYvAu5CRzQ "Upload Software Bill of Materials (SBOM) files manually.") and [Uploading Software Bill of Materials files using a REST API](https://servicenow-prod.fluidtopics.net/to1IyWxue63sIxy_DLj7RQ "Review the following information prior to uploading Software Bill of Materials files using an API.") for more information.

*[\>]: and then


