Only three in 10 respondents said their application security programs were highly mature.