An overlay that adds controls, enhancements, or additional guidance to security control baselines in order to highlight or address needs specific to the purpose of the overlay. (See “overlay.”)
Source(s):
NIST SP 800-161