Would be nice, but I think since (a-e) weren't in that line and that (g) is directly addressing that, that would be incredibly bad wording.
Regardless, I can imagine there are some products with 'essential functions' which require the channel that could be DDOSd, no?
My stance here is that it's very broad, and I think it's easy to create an exploitable system from these directives. But unfortunately the problem is real and the mitigations complex. I was buying into this initially because of that, it seems reasonable without much thought on what the exact solutions look like, which I think makes it more dangerous.
If other engineering fields have seen this process, and the involved regulatory bodies have stayed independent of large corporate interests, I guess we should have a good shot. But with my lack of knowledge on that topic, I hold some trepidation for the future of smaller software shops and individual developers.
> (g) minimise their own negative impact on the availability of services provided by other devices or networks;