There’s an excellent post on Security Principles and Maxims over at http://blog.blackswansecurity.com/2011/04/security-principles-maxims/
When discussing the ubiquitous and nebulous “Best Practice”, it’s handy to have an actual list of what that is - and this is a great start.