---
title: DevOps Practices Mature as Certificate Security Policies Remain Relaxed
description: Cryptographic keys and digital certificates used to uniquely identify machines or applications are vital to businesses that want to guarantee the integrity of in-transit data. However, even businesses with mature DevOps practices sometimes fail to follow practices designed to secure the use and storage of cryptographic keys and digital certificates.
image: https://businessinsights.bitdefender.com/hubfs/devops-practices-mature-as-certificate-security-policies-remain-relaxed-1.jpg
---

[![](https://businessinsights.bitdefender.com/hubfs/2021/09/logo-white.svg)](https://businessinsights.bitdefender.com/?hsLang=en-us)

[![CONTACT AN EXPERT](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd)

- [For Home](https://www.bitdefender.com/solutions/)
- [For Business](https://www.bitdefender.com/business/)
- [Resources](https://www.bitdefender.com/business/resource-library.html)
- [Webinars](https://www.bitdefender.com/business/webinars.html)

# [BUSINESS INSIGHTS](https://businessinsights.bitdefender.com/?hsLang=en-us)

[#Enterprise Security](https://businessinsights.bitdefender.com/topic/enterprise-security) [#Privacy and Data Protection](https://businessinsights.bitdefender.com/topic/privacy-and-data-protection)

 By [**Liviu Arsene**](https://businessinsights.bitdefender.com/author/liviu-arsene) / Apr 25, 2017

# DevOps Practices Mature as Certificate Security Policies Remain Relaxed

Share this [![Share on email](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/email-color.png)](mailto:?subject=Check%20out%20https://businessinsights.bitdefender.com/devops-practices-mature-as-certificate-security-policies-remain-relaxed&utm_medium=social&utm_source=email%20&body=Check%20out%20https://businessinsights.bitdefender.com/devops-practices-mature-as-certificate-security-policies-remain-relaxed&utm_medium=social&utm_source=email) [![Share on twitter](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https://businessinsights.bitdefender.com/devops-practices-mature-as-certificate-security-policies-remain-relaxed&utm_medium=social&utm_source=twitter&url=https://businessinsights.bitdefender.com/devops-practices-mature-as-certificate-security-policies-remain-relaxed&utm_medium=social&utm_source=twitter&source=tweetbutton&text=) [![Share on linkedin](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://businessinsights.bitdefender.com/devops-practices-mature-as-certificate-security-policies-remain-relaxed&utm_medium=social&utm_source=linkedin) [![Share on facebook](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/facebook-color.png)](http://www.facebook.com/share.php?u=https://businessinsights.bitdefender.com/devops-practices-mature-as-certificate-security-policies-remain-relaxed&utm_medium=social&utm_source=facebook)

Cryptographic keys and digital certificates used to uniquely identify machines or applications are vital to businesses that want to guarantee the integrity of in-transit data. However, even businesses with mature DevOps practices sometimes fail to follow practices designed to secure the use and storage of cryptographic keys and digital certificates.

While [82 percent](https://www.helpnetsecurity.com/2017/04/19/devops-settings/) of organizations with mature DevOps practices have consistent policies designed to secure cryptographic keys and digital certificates, only 53 percent of those that have just started to adopt DevOps practices enforce the practices. This means that, while 62 percent of mature DevOps teams replace development certificates with production certificates, only 36 percent of companies that have just started to adopt DevOps teams perform the same tasks.

Some 56 percent of respondents that have just begun to adopt DevOps say their teams are aware of security control for protecting cryptographic keys and digital certificates, while 89 percent of mature DevOps teams believe they have the right security practices in place.

The lack of proper security controls or the ability to distinguish between testing and production certificates can generate serious problems for organizations, as attackers can leverage these issues and exploit them. Considering that 69 percent of mature DevOps teams re-use cryptographic keys - compared to 79 percent of those just adopting DevOps – cybercriminals could gain access to various environments or applications that use that particular key, if it were lost.

In terms of how adopting DevOps can become more professional and move faster to streamline security and improve workflows, [here are some successful DevOps habits](https://businessinsights.bitdefender.com/7-habits-successful-secure-rugged-devops-teams?hsLang=en-us) that they can abide by:

1. Increase trust and transparency between Dev, Sec and Ops
2. Understand the probability and impact of specific risks
3. Discard detailed security road maps in favor of incremental improvements
4. Use the continuous delivery pipeline to incrementally improve security practices
5. Standardize third-party software and then keep current
6. Govern with automated audit trails
7. Test preparedness with security games

### Explore More Topics

- [Enterprise Security (743)](https://businessinsights.bitdefender.com/topic/enterprise-security)
- [Threat Research (201)](https://businessinsights.bitdefender.com/topic/threat-research)
- [Cloud Security (174)](https://businessinsights.bitdefender.com/topic/cloud-security)
- [SMB Security (170)](https://businessinsights.bitdefender.com/topic/smb-security)
- [Ransomware (166)](https://businessinsights.bitdefender.com/topic/ransomware)
- [Privacy and Data Protection (137)](https://businessinsights.bitdefender.com/topic/privacy-and-data-protection)
- [Cybersecurity Awareness (134)](https://businessinsights.bitdefender.com/topic/cybersecurity-awareness)
- [Endpoint Protection & Management (126)](https://businessinsights.bitdefender.com/topic/endpoint-protection-management)
- [Endpoint Detection and Response (124)](https://businessinsights.bitdefender.com/topic/endpoint-detection-and-response)
- [Managed Detection and Response (119)](https://businessinsights.bitdefender.com/topic/managed-detection-and-response)
- [Virtualization & Data Center Security (82)](https://businessinsights.bitdefender.com/topic/virtualization-data-center-security)
- [Threat Intelligence (76)](https://businessinsights.bitdefender.com/topic/threat-intelligence)
- [IT Compliance & Regulations (71)](https://businessinsights.bitdefender.com/topic/it-compliance-regulations)
- [Bitdefender Threat Debrief (55)](https://businessinsights.bitdefender.com/topic/bitdefender-threat-debrief)
- [Managed Service Providers (53)](https://businessinsights.bitdefender.com/topic/managed-service-providers)
- [#Featured (52)](https://businessinsights.bitdefender.com/topic/featured)
- [Advanced Persistent Threats (46)](https://businessinsights.bitdefender.com/topic/advanced-persistent-threats)
- [Events (38)](https://businessinsights.bitdefender.com/topic/events)
- [Independent Testing (18)](https://businessinsights.bitdefender.com/topic/independent-testing)
- [Cybersecurity Advisory Services (9)](https://businessinsights.bitdefender.com/topic/cybersecurity-advisory-services)
- [Podcast (3)](https://businessinsights.bitdefender.com/topic/podcast)
- [top (2)](https://businessinsights.bitdefender.com/topic/top)

See all topics

### Subscribe to Blog Updates

## Read more about this topic

<https://businessinsights.bitdefender.com/quantum-computing?hsLang=en-us>

### [Is Your Data Safe from Quantum Supremacy?](https://businessinsights.bitdefender.com/quantum-computing?hsLang=en-us)

<https://businessinsights.bitdefender.com/upgrading-cryptography-to-a-post-quantum-secure-state?hsLang=en-us>

### [Upgrading Cryptography to a Post-Quantum Secure State](https://businessinsights.bitdefender.com/upgrading-cryptography-to-a-post-quantum-secure-state?hsLang=en-us)

<https://businessinsights.bitdefender.com/downtime-can-cost-a-company-up-to-67-million-over-two-years-threatening-brand-reputation?hsLang=en-us>

### [Downtime Can Cost a Company up to $67 Million Over Two Years, Threatening Brand Reputation](https://businessinsights.bitdefender.com/downtime-can-cost-a-company-up-to-67-million-over-two-years-threatening-brand-reputation?hsLang=en-us)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2685110570-png/Bitdefender-Mar2015-Theme/Images/avatar_img_footer.png)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2676149282-png/Bitdefender-Mar2015-Theme/Images/logo_white_footer.png)

- [![https://twitter.com/Bitdefender_Ent](https://businessinsights.bitdefender.com/hs-fs/file-2658233851-png/Bitdefender-Mar2015-Theme/Images/ft_soc_tw.png?width=33&name=ft_soc_tw.png)](https://twitter.com/Bitdefender_Ent)
- [![Linkedin-icon-300x300](https://businessinsights.bitdefender.com/hs-fs/hubfs/Bitdefender-Mar2015-Theme/Images/Linkedin-icon-300x300.png?width=33&name=Linkedin-icon-300x300.png)](https://www.linkedin.com/company/bitdefender-gravityzone-enterprise-security)
- [![](https://businessinsights.bitdefender.com/hs-fs/file-2676149307-png/Bitdefender-Mar2015-Theme/Images/ft_soc_yt.png)](https://www.youtube.com/user/BitdefenderSecurity)

- [Legal Terms](https://www.bitdefender.com/legal/)
- [Privacy Policy](https://www.bitdefender.com/site/view/legal-privacy-policy-for-bitdefender-websites.html)
- [EULA](https://www.bitdefender.com/site/view/legal-eula.html)
- [Contact Us](https://www.bitdefender.com/business/contact.html)

Copyright © 1997-2023 Bitdefender All rights reserved.

![](https://px.spiceworks.com/px/5rec)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Liviu Arsene",
    "url" : "https://businessinsights.bitdefender.com/author/liviu-arsene"
  },
  "datePublished" : "2017-04-25T13:35:57.000Z",
  "headline" : "DevOps Practices Mature as Certificate Security Policies Remain Relaxed",
  "image" : [ "https://businessinsights.bitdefender.com/hubfs/devops-practices-mature-as-certificate-security-policies-remain-relaxed-1.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://businessinsights.bitdefender.com/devops-practices-mature-as-certificate-security-policies-remain-relaxed",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://businessinsights.bitdefender.com/hubfs/Bitdefender_Logo_Transparent-2.png"
    },
    "name" : "Bitdefender"
  }
}
```