Combined Unified Security Exposure Management release notes for upgrades from Yokohama to Zurich
Summarize
Summary of Combined Unified Security Exposure Management Release Notes for Upgrades from Yokohama to Zurich
The Zurich release of Unified Security Exposure Management (USEM) introduces a major architectural upgrade from Yokohama, offering a unified platform to enhance performance, scalability, and streamlined workflows across Vulnerability Response applications. This release consolidates multiple security exposure management functions into a centralized workspace and administration console, providing a modular, role-based, and future-ready environment for managing security exposures efficiently.
Show less
Upgrade Preparation and Migration
- USEM is available to customers entitled to Vulnerability Response, but migrating to USEM requires careful planning as it is a significant upgrade.
- A Migration Assistant update set is provided to guide plugin installation, data mapping, rule migration, and post-migration validation to reduce risk and manual effort.
- All existing integrations and workflows should be reviewed for compatibility before migration.
Key Features
- Security Exposure Management Workspace: A centralized platform with multiple views:
- Findings View: Offers comprehensive filtering, dashboard creation, and visualization controls for efficient analysis and prioritization.
- Remediation View: Supports multiple work modes (tasks, findings, assets) to facilitate remediation strategies.
- Approval View: Enhanced Exception Management UI improves insights within Change Approval records, speeding up approval workflows by reducing navigation and manual effort.
- Administration Console: Provides one-stop configuration for all USEM applications including assignment rules, classification rules, and remediation targets, ensuring consistent workflows across Vulnerability Response, Application Vulnerability Response, Container Vulnerability Response, and Configuration Compliance.
- Centralized Approval Experience: The Employee Service Center (ESC) now delivers a standardized approval interface for stakeholders who do not regularly use USEM, improving approval efficiency.
- Unified Approval Rules: Administrators can configure approval workflows across multiple findings and remediation task tables through a single interface, including multi-level approvers and condition settings.
- Cloud Exposure View: Consolidates cloud-related security findings from various vendors, enabling cloud security teams to monitor posture centrally.
- Integration Monitoring: Built-in monitoring in the Administration Console allows administrators to view and troubleshoot integration run statuses, improving operational health.
- Generative AI Insights: Now Assist integration delivers AI-powered contextual summaries and actionable recommendations on dashboards to prioritize risks and speed decision-making.
- Custom Visualization Widgets: Users can create and manage custom widgets in the Findings view to tailor dashboards to organizational reporting needs and focus on relevant security metrics.
- Dynamic Remediation Target Dates: Remediation target dates automatically recalculate based on updated risk ratings to maintain accurate SLA tracking.
- Enhanced Exception Management: Supports flexible manual and automated exception workflows with detailed tracking and audit trails to simplify compliance and reporting.
- Unified Task Management: Centralized rule definition and support for manual and automated remediation task creation across all USEM applications.
- Advanced Risk Management: Introduction of risk calculators and risk rollup calculators to consistently score risks across applications.
- AI-Powered Recommendations for Exceptions: On-demand AI advice to approve or reject exception and false positive requests directly within the Exception Change Approval records, improving decision speed and consistency.
- Change Approval Enhancements: Includes automatic Change Approval creation for exception rule submissions, vulnerability intelligence tiles with critical threat context, impact summary tiles for approval visibility, application-based filtering in approvals, and the ability to reapply assignment rules for deferred or manually assigned items.
- Dark Theme Support: The new Coral theme supports a dark mode option for web and mobile interfaces to enhance usability.
Activation and Requirements
- USEM is a ServiceNow AI Platform feature activated via the Security Exposure Management plugin (com.snc.securitysupport.core).
- There are no new additional requirements or browser changes introduced in Zurich for USEM.
Practical Benefits for ServiceNow Customers
- Centralized and unified management of security exposures across multiple vulnerability response modules simplifies operations and reduces complexity.
- Improved workflows and AI-driven insights accelerate risk prioritization, remediation, and approval processes.
- Standardized configuration and approval interfaces increase efficiency and transparency for security teams and approvers.
- Enhanced exception management and audit trails support compliance and regulatory needs.
- Modular architecture and cloud exposure visibility future-proof the security exposure management capabilities within ServiceNow.
Consolidated page of all release notes for Unified Security Exposure Management from Yokohama to Zurich.
How to use this page
To help you prepare for your upgrade, we have combined the cross-family Unified Security Exposure Management release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Yokohama to Zurich.
Important information for upgrading Unified Security Exposure Management to Zurich
Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
Unified Security Exposure Management is available to all customers who are entitled to Vulnerability Response, however, migrating to USEM is a major upgrade that introduces a unified architecture for improved performance, scalability, and streamlined workflows. Before upgrading, leverage the Migration assistant for Unified Security Exposure Management that is available as an update set. See the Migration Guidance to Unified Security Exposure Management [KB2556844] Knowledge Base article for more information. This tool provides a guided experience for plugin installation, data mapping, rule migration, and post-migration validation, reducing risk and manual effort. Ensure that all integrations and workflows are reviewed for compatibility before initiating migration. For more information, see Migrating to USEM and Migrate to USEM. |
New features
Between your current release family and Zurich, new features were introduced for Unified Security Exposure Management.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
|
Changes
Between your current release family and Zurich, some changes were made to existing Unified Security Exposure Management features.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Removed
Between your current release family and Zurich, some Unified Security Exposure Management features or functionality were removed.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Deprecations
Between your current release family and Zurich, some Unified Security Exposure Management features or functionality were deprecated.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Activation information
Review information on how to activate Unified Security Exposure Management.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
Unified Security Exposure Management is a ServiceNow AI Platform feature that is available with activation of the Security Exposure Management (com.snc.security_support.core). For details, see Install Unified Security Exposure Management. |
Additional requirements
If any additional requirements were introduced or changed for Unified Security Exposure Management we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Browser requirements
If any specific browser requirements were introduced or changed for Unified Security Exposure Management we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Accessibility information
Review details on accessibility information for Unified Security Exposure Management, such as specific requirements or compliance levels.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
|
Localization information
If there are specific localization considerations for Unified Security Exposure Management we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Highlight information
If there are specific highlight considerations for Unified Security Exposure Management we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
See Unified Security Exposure Management for more information. |