Home > Published Issues > 2026 > Volume 21, No. 4, 2026 >
JCM 2026 Vol.21(4): 481-482
Doi: 10.12720/jcm.21.4.481-492

Review of Security-aware Software Engineering Frameworks for Internet of Things

Nada Mohammed Hassan Moter1, Mustafa Moosa Qasim2,*, Mohanad Ahmed Abdulrazzaq Diwan Alzamili3, Mahmood A. Al-Shareeda4,5,*, Mohammed Amin6, and Rami Shihab7
1Pharmacy Department, Medical Technical Institute-Basra, Southern Technical University, Basra, Iraq
2Department of Intelligent Medical Systems, College of Computer Science and Information Technology, University of Basrah, Basrah, Iraq
3Department of Computer Networking and Software Techniques, Basra Technical Institute, Southern Technical University, Basra, Iraq
4Department of Electronic Technologies, Basra Technical Institute, Southern Technical University, Basra, Iraq
5College of Engineering, Al-Ayen University, Thi-Qar, Iraq
6King Abdullah the II IT School, Department of Computer Science, The University of Jordan, Amman, Jordan
7Vice-Presidency for Postgraduate Studies and Scientific Research, King Faisal University, Al-Ahsa, Saudi Arabia
Email: tsnada2016@stu.edu.iq (N.M.H.M.); mustafa_mq87@uobasrah.edu.iq (M.M.Q.); mohanad.a.abdulrazaq@stu.edu.iq (M.A.A.D.A.); mahmood.alshareedah@stu.edu.iq (M.A.A.-S.); m.almaiah@ju.edu.jo (M.A.); rtshehab@kfu.edu.sa (R.S.)
*Corresponding author

Manuscript received December 20, 2025; revised January 12, 2026; accepted February 28, 2026; published July 17, 2025.

Abstract—Internet of Things (IoT) environments are rapidly growing, which in turn has accelerated security threats that are often mitigated by re-activistic deployment-stage controls rather than actively embedded throughout the software development process. Although many other works suggest technical security solutions, little is understood about the process by which security is managed throughout the Software Development Life Cycle (SDLC). This paper provides a systematic literature review of the security aware software engineering frameworks for IoT systems proposed from 2018 to 2025, along with the definition of six dimensions in order to help with its classification and comparison. This taxonomy is organized along six distinct dimensions: (i) phases of SDLC security integration, (ii) categorization of security frameworks, (iii) core security objectives, (iv) trust and adversarial threat premises, (v) contextual limitations imposed by IoT deployments, and (vi) standard of valibation procedures. Comparative analysis conducted via the proposed taxonomy reveals that most existing frameworks prioritize runtime security enforcement and authentication-focused protection targets, rely on implicit or centralized trust paradigms, and suffer from insufficient real-world verifiable validation. Derived from these analytical findings, we identify prominent research gaps spanning full-lifecycle embedded security integration, transparent, verifiable trust modeling, cross-domain framework portability, and repeatable experimental validation methodologies. Beyond its analytical utility, this taxonomy delivers a standardized structural foundation to guide subsequent investigations into
security-by-design engineering workflows tailored for IoT software systems.  
 
Keywords—security-aware software engineering, Security and Operations (DevSecOps), Internet of Things (IoT) security frameworks, software development lifecycle, systematic survey


Cite: Nada Mohammed Hassan Moter, Mustafa Moosa Qasim,  Mohanad Ahmed Abdulrazzaq Diwan Alzamili, Mahmood A. Al-Shareeda, Mohammed Amin,  and Rami Shihab, “Review of Security-aware Software Engineering Frameworks for Internet of Things," Journal of Communications, vol. 21, no. 4, pp. 481-492, 2026.

Copyright © 2026 by the authors. This is an open access article distributed under the Creative Commons Attribution License which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited (CC BY 4.0).
 

 

Article Metrics in Dimensions