The truth lies somewhere in the middle...
If the only VRRP routers are the two neighbors forming the MLAG, then Sumit is right and the ACL should be applied only to the ISC ports.
But if there are other routers taking part of VRRP, other than the two neighbors forming the MLAG, then the ACL should be applied to any other ports that would let the hello packets reach these other VRRP members, as one of these might become Master and force the rest to standby.
Regards ,Daniel