An ACL is used to filter incoming or outgoing traffic of an interface, whether it's on a Cisco router or ASA. Without the ACL, any type of traffic will be allowed to flow freely between network/interfaces and this can be a security concern.
Let's imagine you work in the IT department of your organization. Within the department, there is a small server room without any access controls (no locks on the door or keypad entry). This would mean anyone who's in the IT department, whether a visitor, a member of staff, or even an intern, would be able to simply walk into the server room without providing identification or even requiring prior authorization.
Simply installing physical access controls, such a keypad lock on the door, will deter people without the correct combination of the PIN. In other words, only those who are allowed entry...