Reviewing the Components module in the Software Bill of Materials Workspace
Summarize
Summary of Reviewing the Components module in the Software Bill of Materials Workspace
The Components module in the Software Bill of Materials (SBOM) Workspace provides crucial insights into the status of your imported components, highlighting those that are vulnerable, stale, abandoned, or high-risk. Users with the role ofsnsbomresp.sbomanalystcan navigate to this module viaWorkspaces > SBOM Workspace > Components. The data displayed is refreshed daily, enhancing reporting performance without affecting data storage.
Show less
Key Features
- Installed Application Insights:
- SBOM Core: Displays an inventory of uploaded components including name, description, version, and BOM entity count.
- SBOM Response: Allows users to interact with graphical representations of data to view associated records.
- Component Classification:
- Stale Components: Versions more than two major releases behind and over two years old.
- Abandoned Components: Not updated in over two years.
- Vulnerable Components: Those with High or greater severity vulnerabilities.
- High-Risk Combinations: Identifies stale and abandoned components with severe vulnerabilities that can be resolved through updates or replacements, with fixable status percentages provided.
- Fixability Assessment: Breakdowns of vulnerabilities by severity (Critical, High, Medium, Low) with statuses indicating whether fixes are complete, partial, or not available.
- License Classification: Breakdown of components by license type, aiding in compliance assessment.
Key Outcomes
By utilizing the Components module, ServiceNow customers can effectively manage their component inventory, identify risks associated with vulnerabilities, and ensure compliance with licensing requirements. This module aids in prioritizing components that require immediate attention, facilitating maintenance and risk mitigation strategies in software management.
The Components module in the Software Bill of Materials (SBOM) Workspace displays current information about vulnerable, stale, abandoned, and high-risk combinations for the components you import.
Viewing the Components module
Role required: sn_sbom_resp.sbom_analyst
Navigate to .
What you can see in the module depends on the applications you have installed.
Imported data is not calculated and populated by live queries. Scores on the Home and Components pages are updated once daily with performance enhancements for reporting. This enhancement might provide you with faster load times for the scorecards on the Home and Components modules in the SBOM Workspace.
These enhancements have no impact on how or where data is stored.
| Installed application | Description |
|---|---|
| If you have installed SBOM Core | An inventory of all uploaded components that includes the following information:
|
| If you have installed SBOM Response | Select a graph or a number on the graph to view a list of associated records.
The Component List under the visualizations enables you to see the name, description, version, and entity counts. In the right panel, you can view a version history. The current version is highlighted in the version history. The Common Vulnerabilities and Exposure (CVE) and Fixability columns are also displayed. |
Assessing your risk with vulnerability intelligence
See Checking a Software Bill of Materials entity for vulnerabilities for more information about how to review vulnerability intelligence data in the workspace.
Assessing your risk with license compliance
See Classifying licenses and resolving component licenses in the Software Bill of Materials workspace for more information about how to license data your import with your components and viewing your over-all license compliance in the workspace.