I know that some Wsus administrators create "Software group" instead of Computers group. For example, they create a group named "Flash Player", and another named "Adobe Reader" and so on...
Then, they add computer to these groups. If a computer needs to be keep up to date with Flash player but not Adobe Reader, they add this computer to "Flash Player" group but not "Adobe Reader".
For doing this, you need to desactivate "Client side targeting" via GPO on clients computers and set the Wsus server to allow assigning computer manually (Options -> Computers -> "Use Update Service Console")
Then, they add computer to these groups. If a computer needs to be keep up to date with Flash player but not Adobe Reader, they add this computer to "Flash Player" group but not "Adobe Reader".
For doing this, you need to desactivate "Client side targeting" via GPO on clients computers and set the Wsus server to allow assigning computer manually (Options -> Computers -> "Use Update Service Console")