Few security professionals are likely to forget where they were on December 9, 2021, when a critical vulnerability in the popular Log4j Java logging library was disclosed. The complexity of tracking down Log4j demonstrates the challenges of securing modern applications and the need for a software bill of materials (SBOM). This white paper introduces SBOMs, explains why they’re needed, the role they play in application security, and how to generate them.