Skip to content

OAuth

What is OAuth?

An open standard authorisation protocol that enables applications to obtain limited access to user accounts on third-party services. OAuth 2.0 is widely used for delegated authorisation in web and mobile applications.

Information Security

Each of these is named in at least one of the same controls as oauth. The number is how many controls name both.

What the standards actually require on oauth

Requirements naming oauth across 6 standards, quoted from the control text.

HL7 FHIR Authentication. SMART APP LAUNCH IMPLEMENTATION GUIDE v2.2.0 - foundational FHIR-based OAuth 2.0 / OAuth 2.1 + OpenID Connect framework + standardised app authorization.

HL7-FHIR-Auth-SMART-OAuth-OIDC-Backend · HL7 FHIR Authentication - SMART App Launch + OAuth 2.0 + OpenID Connect + Backend Services + Token Lifetime

NF service consumers must obtain access tokens from the NRF to invoke services on NF service producers. Tokens must be validated for scope, audience, expiry, and signature.

33.501-13.2 · Network Function Service Authorization (OAuth 2.0)

Authentication and authorisation must use OAuth 2.0 and OpenID Connect protocols as specified in the security profile.

OB-SEC.3 · OAuth 2.0 and OpenID Connect

Apply data minimisation + scope enforcement + localisation + cross-border transfers per applicable regulation. Data Minimisation and Scope Enforcement must (a) enforce OAuth scope checking at every API endpoint + (b) return only data within authorised scope +...

OPENBANK-5 · Data Minimisation, Scope Enforcement, Localisation, Cross-Border Transfers

GS1 DATA SECURITY + INTEGRITY in supply chain data exchange. KEY PRINCIPLES: (1) DATA INTEGRITY - master data + EPCIS events + GDSN exchanges must be ACCURATE + COMPLETE + TIMELY + reflect true state of supply chain;

GS1-DataSecurity-Integrity-AccessControl · GS1 Data Security and Integrity in Exchange, Access Control and Tamper Evidence

Questions people ask about oauth

What is OAuth?
An open standard authorisation protocol that enables applications to obtain limited access to user accounts on third-party services. OAuth 2.0 is widely used for delegated authorisation in web and mobile applications.
Why is OAuth important for compliance?
OAuth is a key concept in Information Security. Understanding oauth helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address OAuth?
OAuth appears in the requirement text of HL7 FHIR Security Framework, 3GPP 5G Security Architecture (TS 33.501), UK Open Banking Standard, ITU-T X.805 - Security Architecture for End-to-End Communications, Open Banking Security. Across these standards we have identified 15 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about OAuth?
Explore our compliance framework pages to see how oauth applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how OAuth applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.