Earlier quoted context omitted.
I don't disagree that it's a best practice, or that those best practices are a good idea. Expecting the police to follow those best practices every time is not any more reasonable than expecting any other profession to follow best practice every time. The reason we don't legally require them to prevent crime is that it's an unachievable standard.
I'm sorry, i worked with patient health data, and i'm currently working with people banking informations. Expecting i follow the industry best practice is the MINIMUM. It is reasonable that my employer expect me to store my passowrds/api keys everytime and that i do not publish them on github/gitlab. It is also reasonable that my APIs are protected. Its is also reasonable that i monitor if my services are up or down.…
If your data isn't protected by law in the US, chances are that data processors are most likely not following many data protection best practices.