This document presents a comprehensive framework for integrating security into the software development life cycle (SDLC) using a security-by-design methodology. The proposed framework aims to systematically manage product development to enhance security, drawing on evidence-based approaches such as Common Criteria, ISMS, and PIMS, which provide detailed security activities. The document also summarizes historical contexts and previous works on secure SDLC while introducing a CIA-level driven framework that consolidates various secure SDLC practices.