Security solutions for the Internet of Things (IoT) in smart cities are complex and require a comprehensive approach to success. Several models and frameworks have been developed focusing on IoT security. Some deal with access controls and security and some with authentication and authorization in various forms. Literature still lacks a comprehensive IoT security model for smart cities, which can support the implementation of IoT. Accordingly, this study has set two objectives: to explore the present studies in IoT security for smart cities and to develop an IoT security model for smart cities based on the metamodeling approach. According to the findings of the study, the existing IoT security models for smart cities consider seven security aspects: authentication and authorization, device management, intrusion detection and prevention, device integrity, secure communication, secure data storage, and response to security incidents. The model developed in this study, called IoT Security Metamodel (IoTSM), combines these aspects. IoTSM captures the main qualities of IoT security practices in smart cities through domain security processes.