Publication Date

Spring 2026

Degree Type

Dissertation

Degree Name

Doctor of Education (EdD)

Department

Education

Advisor

Melody Moh; Ferdinand Rivera; Hazel De Ausen

Abstract

This study examines the cybersecurity and data privacy policy guiding the staff in the following four California State University campuses: Long Beach, San Bernardino, Chico, and Northridge. The purpose is to evaluate how institutional policies communicate expectations for staff and support cybersecurity readiness. Using a qualitative document analysis approach, the study analyzes publicly available policy documents as primary data sources. The analysis is guided by three frameworks, as follows: Weidman’s framework (2018), which assesses the presence of key policy elements; Karakoç’s framework (2022), which evaluates the depth of policy content; and the Flesch Reading Ease and Flesch-Kincaid Grade Level formulas (Flesch, 1948; Kincaid et al., 1975), which measure readability. Findings indicate that all four campuses include core cybersecurity components. CSU San Bernardino’s policy provides the most comprehensive and in-depth structure, while CSU Northridge emphasizes user-focused guidance with less formal governance articulation. CSU Long Beach and CSU Chico present moderate levels of coverage with varying degrees of depth and clarity when discussing their cybersecurity and data privacy policies guiding the staff. Across all four campuses, readability scores suggest that many of the stated policies were written at a college or graduate level, which may limit accessibility for nontechnical staff.

Share

COinS