The opening sentence of 5 Security reads:
*****
The recommendations contained in this chapter are provided for guidance only and are not intended to serve as a complete reference on the subject.
*****
and then at the end of the hanging paragraph that starts 5, says:
*****
The remainder of this chapter is Non Normative.
*****
I think the entire chapter is non-normative by its own admission and so could either be marked: Section 5 Security Non-Normative (with appropriate changes to the internal language) or made a non-normative appendix.
Possible action:
remove line 1692 The remainder of this chapter is non normative.
replace 1661 and 1662 with:
This Chapter is provided for guidance only and is Non Normative. However, it is strongly recommended that Server implementations that offer TLS [RFC5246] SHOULD use TCP port 8883 [IANA service name: secure-mqtt].