2026-06-29
2026-04-24
2026-02-26
Manuscript received December 20, 2025; revised January 12, 2026; accepted February 28, 2026; published July 17, 2025.
Abstract—Internet of Things (IoT) environments are rapidly growing, which in turn has accelerated security threats that are often mitigated by re-activistic deployment-stage controls rather than actively embedded throughout the software development process. Although many other works suggest technical security solutions, little is understood about the process by which security is managed throughout the Software Development Life Cycle (SDLC). This paper provides a systematic literature review of the security aware software engineering frameworks for IoT systems proposed from 2018 to 2025, along with the definition of six dimensions in order to help with its classification and comparison. This taxonomy is organized along six distinct dimensions: (i) phases of SDLC security integration, (ii) categorization of security frameworks, (iii) core security objectives, (iv) trust and adversarial threat premises, (v) contextual limitations imposed by IoT deployments, and (vi) standard of valibation procedures. Comparative analysis conducted via the proposed taxonomy reveals that most existing frameworks prioritize runtime security enforcement and authentication-focused protection targets, rely on implicit or centralized trust paradigms, and suffer from insufficient real-world verifiable validation. Derived from these analytical findings, we identify prominent research gaps spanning full-lifecycle embedded security integration, transparent, verifiable trust modeling, cross-domain framework portability, and repeatable experimental validation methodologies. Beyond its analytical utility, this taxonomy delivers a standardized structural foundation to guide subsequent investigations into security-by-design engineering workflows tailored for IoT software systems. Keywords—security-aware software engineering, Security and Operations (DevSecOps), Internet of Things (IoT) security frameworks, software development lifecycle, systematic survey