andy_ojha
ServiceNow Employee

usem_update_set_banner_v5.svg

 

As you explore USEM (VR v30x), either as an existing customer that has recently migrated or as a brand new customer starting your journey, you will need to make a plan for managing and promoting your configurations (aka USEM rules) between ServiceNow Instances.  

 

Assignment Rules, Classification Rules, Remediation Targets, and others managed through the USEM Administration experience — are not automatically captured in update sets. This can create friction as you establish your configuration promotion path across DEV → TEST → STAGE → PROD ServiceNow instances.

 

As of VR v30.3.3 (April 9, 2026), there's a new "Add to Update Set" feature that makes this significantly easier. You can now capture USEM configurations directly into update sets from the Security Exposure Management Workspace (Administration panel), and promote these update sets between ServiceNow instances.

 

andy_ojha_0-1779976858006.png

 

The attached guide walks through the process:

• Prerequisites (including a one-time Script Include import for pre-Brazil instances)
• How to create an update set and use the Add to Update Set button
• How to export, import, preview, and commit the update set on your target instance
• Verification steps to confirm your configurations landed successfully

 

The utility that introduces the "Add to Update Set" feature to the Security Exposure Management Workspace, requires being on VR v30.3.3 (Apr 2026) or higher.  Additionally, if your ServiceNow instance is on a platform version before Brazil (e.g. Yokohama, Zurich, Australia) you will need to do a (one-time) import of a Script Include that is attached to the Support KB below:


For those using prior versions of USEM before April 2026 (i.e. VR v30.1.4 to VR v30.2.5), migrating USEM Rules and Configurations can be achieved manually, using XML export/import functionality and the tables documented in the Support KB below:

 

Version history
Last update:
58m ago
Updated by:
Contributors