Publication Date
Spring 2026
Degree Type
Dissertation
Degree Name
Doctor of Education (EdD)
Department
Education
Advisor
Melody Moh; Ferdinand Rivera; Hazel De Ausen
Abstract
This study examines the cybersecurity and data privacy policy guiding the staff in the following four California State University campuses: Long Beach, San Bernardino, Chico, and Northridge. The purpose is to evaluate how institutional policies communicate expectations for staff and support cybersecurity readiness. Using a qualitative document analysis approach, the study analyzes publicly available policy documents as primary data sources. The analysis is guided by three frameworks, as follows: Weidman’s framework (2018), which assesses the presence of key policy elements; Karakoç’s framework (2022), which evaluates the depth of policy content; and the Flesch Reading Ease and Flesch-Kincaid Grade Level formulas (Flesch, 1948; Kincaid et al., 1975), which measure readability. Findings indicate that all four campuses include core cybersecurity components. CSU San Bernardino’s policy provides the most comprehensive and in-depth structure, while CSU Northridge emphasizes user-focused guidance with less formal governance articulation. CSU Long Beach and CSU Chico present moderate levels of coverage with varying degrees of depth and clarity when discussing their cybersecurity and data privacy policies guiding the staff. Across all four campuses, readability scores suggest that many of the stated policies were written at a college or graduate level, which may limit accessibility for nontechnical staff.
Recommended Citation
Hung-Nguyen, Andrew, "Selected California State University Cybersecurity Readiness Policies and Related Guidance for Staff: A Qualitative Document Analysis" (2026). Dissertations. 139.
DOI: https://doi.org/10.31979/etd.pnk4-st3n
https://scholarworks.sjsu.edu/etd_dissertations/139