Review a software bill of materials submission from an engagement
Track processing status and review the outcome of a SBOM submission from an engagement, including successful upload, failed upload, and decline.
Before you begin
To update manufacturer data in the SBOM workspace, ensure that you have edit access to the CMDB (configuration management database) product model table.
Role required: sn_vdr_risk_asmt.vendor_risk_manager or sn_vdr_risk_asmt.vendor_risk_assessor
About this task
SBOM information is collected through the engagement-level external assessment. After the engagement contact submits the assessment in the third-party portal, post-assessment processing sends the uploaded file to the SBOM API, provided by Unified Security Exposure Management (USEM) (Unified Security Exposure Management), and records status updates. To troubleshoot API processing issues, see the Unified Security Exposure Management (USEM) documentation.
Third-party assessment reviewers can view SBOM component records on engagement and third-party records but can't access the SBOM workspace.
Procedure
What to do next
After reviewing the submission outcome, use the information to support your risk evaluation:
- Review SBOM document and component records on the engagement to assess the engagement's software inventory.
- If your instance includes the SBOM Response application and Vulnerability Response, review vulnerability details at the component level.
- If the engagement declined to provide an SBOM, consider the declination as part of your overall risk assessment and determine whether additional due diligence steps are required.