Best Practices is of course in most cases "Subjective" so we will try to error on the side of security.
Best Practices also requires a well defined context so that they are implemented within the same design.
Most of these documents will be linked to this list: