Which of the following is not part of the process for assessing security controls according to NIST SP 800 53A 1?

(A) Study
(B) Develop
(C) Conduct
(D) Analyze