Yes, that's correct.
You will need to apply the ACL to your outside interface -
access-group 101 in interface outside (as example)
Depending on your config, you may need to assign a static NAT to your server.
static (inside,outside) public.ip.address internal.ip.address netmask 255.255.255.255