Sure it can (we do it). You just need to translate from outside to inside. Here is an example, assume ACS is 192.168.1.10.
static (inside,outside) 192.168.1.10 access-list TACACS tcp 65535 10000
Since the static uses an ACL, here is that part as well-
access-list TACACS extended permit ip host 192.168.1.10 host [public IP]
The public IP in our case is the internet router and it requires a static route for the private IP pointing to the firewall.
Hope that helps.