You use ACLs for main purposes:
Security filtering: Block unwanted traffic like malicious IPs or dangerous protocols from entering your network.
Traffic control: Limit which internal hosts can access external resources. For example, only allow servers to reach the internet.
Network policy: Enforce organizational rules. Perhaps only the HR subnet can access payroll servers.