# Nexus Repository Best Practices: Cleanup Policies, Part 2

**URL:** <https://community.sonatype.com/t/nexus-repository-best-practices-cleanup-policies-part-2/11593>\
**Category:** Best Practices\
**Tags:** nexus-repository, blob, sbom, blob-store, cleanup\
**Created:** [November 13, 2023, 3:43pm UTC](https://community.sonatype.com/t/nexus-repository-best-practices-cleanup-policies-part-2/11593 "2023-11-13T15:43:39Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![jzora](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/jzora/32/4197_2.png) [@jzora](https://community.sonatype.com/u/jzora)\
**Post date:** [November 21, 2023, 9:12pm UTC](https://community.sonatype.com/t/nexus-repository-best-practices-cleanup-policies-part-2/11593/3 "2023-11-21T21:12:17Z")

</div>

Hi, Ingmar! Sorry for the delayed reply. That’s a very good question.

The arguments for storing your SBOMs separately from artifacts are:

- SBOMs are not called, used, or distributed in the same way as artifacts
- Easier access controls: the people who need access to artifacts aren’t identical to the people who need access to SBOMs

But the argument for storing SBOMS alongside artifacts are:

- Makes security reviews easier
- Makes scanning with Lifecycle simpler
- Adds context to your SBOMs
- Potentially easier to configure with your CI/CD process

To answer your question: in the ideal scenario, you’d keep a copy of the SBOM alongside the artifacts, with another copy in a separate repository for distribution to vendors, regulatory purposes, etc. But it really all depends on what your organization is doing with SBOMs.

---

_[View the full topic](https://community.sonatype.com/t/nexus-repository-best-practices-cleanup-policies-part-2/11593)._
