Each spec should have a "security considerations" section. We could say in the security considerations section that:

 * Many applications will want to encrypt data. They should do so according to their needs.
 * W3C has a WebCrypto API for doing so interoperably:

So maybe that is "option 3, but with some pointers to relevant work such as WebCrypto API"


