I propose to have sections more aligned with NIST SP 800-63:
- BCP
- Definition of considered authenticators: Definition, characteristics, requirements for enrollment, management,and usage
- Definition of supporting component for authentication: Definition, characteristics, requirements for enrollment, management,and usage
- Maturity Model: Definition, eligible authenticator, eligible supporting components
- We should limit at 4, 3 is even better to match other xAL
- Security section about threats and mitigations
I propose to have sections more aligned with NIST SP 800-63: